Luxembourg Sanctions Risk Assessment: Screening Gaps the CSSF Flagged

The Luxembourg sanctions risk assessment that the CSSF drew to supervised firms’ attention in a communiqué of 24 September 2026 is the country’s first vertical risk assessment (VRA) of targeted financial sanctions (TFS) linked to terrorist financing (TF) and proliferation financing (PF). The Ministry of Finance led the exercise and released the report, titled “PF and TF TFS VRA” and dated June 2026, on 21 September 2026. The CSSF, the other AML/CFT supervisors, the self-regulatory bodies and the Cellule de Renseignement Financier (CRF) contributed data and analysis.

Two parts of the report bear directly on compliance work inside CSSF-supervised firms. The sector tables give every CSSF sub-sector examined in depth an inherent and a residual rating, and all of them end at Low residual risk except wholesale, corporate and investment banking, which stays at Medium. The mitigating-factors chapter then reproduces the CSSF’s own supervisory case files on sanctions screening: a bank that screened twice a month, a bank whose sanctions lists went a year without an update, an e-money institution that left part of its client base out of daily screening. All three ended in administrative fines, and the two bank fines were published by name.

Both parts feed documented work. Article 2-2(2) of the Law of 12 November 2004 requires professionals to ensure that risk information in the national and supranational risk assessments, or communicated by supervisory authorities, is incorporated into their own risk assessment, and to keep that assessment documented and up to date. Read with the CSSF communiqué, that duty in my reading reaches the VRA’s relevant risk information; Article 2-2(2) does not prescribe adopting the VRA’s sector rating as the firm’s own rating. The case files tell a sanctions team which screening controls to retest first.

Related reading: AML Reporting in Luxembourg

Key dates behind the Luxembourg sanctions risk assessment

  • 2018 to 2023: observation period; most sector statistics are stated as at 31 December 2023.
  • June 2026: date on the Ministry of Finance report.
  • 21 September 2026: Ministry of Finance press release publishing the VRA.
  • 24 September 2026: CSSF communiqué to supervised entities.
  • 10 July 2027: Regulation (EU) 2024/1624 (AMLR) applies.

The communiqué’s list of entity types it is relevant for is wider than the set of sub-sectors the report rates. It includes credit servicers, crowdfunding service providers and securitisation undertakings, none of which received a deep-dive rating in the VRA. For those firms the report still supplies the threat analysis and the supervisory expectations, but no sector score to copy into the risk assessment.

What the VRA measures, and what sits outside it

The report borrows its central definition from FATF Recommendation 1 as revised in 2020: PF risk refers “strictly and only” to the potential breach, non-implementation or evasion of the targeted financial sanctions obligations in FATF Recommendation 7. The VRA spells out the consequence. Its ratings measure the risk of failing to apply the in-scope targeted financial sanctions to designated persons, and the wider risk of proliferation activity itself is left outside. The same lens is applied to TF, which is why the report leaves suspicious transaction reporting for terrorist financing out of scope and points back to Luxembourg’s 2022 TF vertical risk assessment for it.

The regimes covered are a subset of the sanctions that apply in Luxembourg. For PF, the report covers the UN and EU measures on the Democratic People’s Republic of Korea (DPRK) and Iran. For TF, it covers the UN listings for Al-Qaida, ISIL and the Taliban plus EU regimes for thirteen countries, from Afghanistan to Yemen, that the report selected on two stated criteria: a UN or EU sanctions regime and a top-50 ranking in the Global Terrorism Index. With the DPRK, the report calls these the “in-scope countries”, and most of its sector statistics on geographic exposure are measured against that list.

Russia-related measures fall outside the definition. The report does say that several of the supervisory measures it cites originated in the supervision of other regimes, in particular the restrictive measures adopted over the war against Ukraine, and that evasion techniques carry across regimes. A Low residual rating for a sub-sector in this VRA is therefore a statement about the DPRK, Iran and the TF regimes. It says nothing about a firm’s exposure under Regulation (EU) No 269/2014 or the other Russia-related acts.

How the CSSF-supervised sub-sectors were rated

Each sub-sector received an inherent score from 1 to 5, averaged across six dimensions from market size to distribution channels. Mitigating factors were scored separately and subtracted: “significant” mitigating factors take 1.00 off the inherent score, “very high” ones take 2.00. For the banking, investment, MVTS, VASP and specialised PFS sectors under CSSF supervision, the report adds that no entity has shareholders from an in-scope country.

Sub-sector (CSSF-supervised) Inherent risk Residual risk Driver the VRA names
Retail and business banks, including those operating online Medium Low Very high client numbers and the distribution model
Wholesale, corporate and investment banks High Medium Correspondent banking and trade finance products, clients, distribution model
Private banking Medium Low Higher-risk clients, notably high-net-worth clients, including from remote jurisdictions
Custodians and sub-custodians, including CSDs Medium Low Intermediary accounts held for other professionals
Collective investments Medium Low Size and cross-border distribution
Wealth managers (portfolio managers and investment advisers) Medium Low High-net-worth clients and customer due diligence performed by third parties
Payment institutions, e-money institutions, and agents and e-money distributors of PIs/EMIs from other EU Member States Medium Low Transaction volume, client numbers, online distribution
Virtual asset service providers Medium Low Services offered, volume, speed and irreversibility of transfers
Specialised PFS providing corporate services Medium Low Size of the sector and client types

Two readings of the table would mislead. The first treats a blank as a pass. Broker-dealers, regulated securitisation vehicles and support PFS, among others, appear in grey with no rating because they were not selected for a deep dive, and the report states that a sector left out of the in-depth analysis can still be vulnerable to non-compliance with financial sanctions. A firm in one of those sub-sectors has no national score to cite, which leaves the rating work to its own assessment.

The second reading stops at the firm’s own row. The highest ratings in the whole report sit with the customers CSSF-supervised firms onboard. Domestic fiducies, foreign trusts, and ASBLs and fondations that meet the FATF definition of a non-profit organisation and operate abroad all end at Very High residual risk; sociétés commerciales end at High. A private bank rated Low as a sub-sector can hold a book of clients whose legal forms the same report rates High or Very High, and the customer-risk side of the assessment is where that belongs.

Wholesale and correspondent banking: the one CSSF row left at Medium

Wholesale, corporate and investment banking is the only CSSF sub-sector that starts at High, and it finishes at Medium. The VRA ties the rating to the product suite. About a quarter of Luxembourg banks offer trade finance or correspondent banking services, and a handful of correspondent banks hold more than 85% of all correspondent banking relationships. No VOSTRO account opened with a Luxembourg bank was held by a respondent bank established in an in-scope country, but about 12% of those accounts belonged to respondent banks established outside the EU, and the report notes that the respondent bank’s own clients or counterparties may still be linked to designated persons. Under 1% of the sub-sector’s 2023 payments related to higher-risk countries on the CSSF’s internal classification, which covers financial crime in general and so does not isolate in-scope countries.

Trade finance has its own supervisory history. A thematic on-site inspection launched in 2022 and carried out in 2023 looked at trade finance activity relevant to PF and TFS risk, and the CSSF asked for better formalisation of the analysis performed, in particular on trading routes and on the nature of the traded goods. During its thematic TFS inspections of 2022 and 2023, the CSSF also drew professionals’ attention to sectoral sanctions that require an in-depth review of transactions originating from, or addressed to, a country subject to targeted financial sanctions.

The data trail matters as much as the analysis. One CSSF case file started from flow data exchanged with the Banque centrale du Luxembourg: a bank had reported wire transfers with the DPRK. On follow-up, the bank found the payments originated in another country, and the DPRK country code (KP) in its report came from a technology coding issue that was then fixed. Through its updates of Circular CSSF 22/822 on FATF statements, the CSSF also requires professionals to inform it of any correspondent banking relationship with a credit institution from Iran or the DPRK. According to the VRA, it has not been informed of any.

Funds and wealth managers: exposure through distribution and delegated CDD

For collective investments, the VRA accepts that medium- to long-term strategies rarely suit someone trying to move money quickly; the pressure points are size, cross-border distribution and asset class. Alternative investment funds investing in private equity and real assets present higher product risk in the report’s assessment, though they account for a small share of assets under management. Distribution of Luxembourg funds into in-scope countries represented less than 0.003% of total assets under management in 2023, a figure the report itself says may be subject to reporting errors.

Wealth managers show the same shape on a smaller scale. At 31 December 2023, 71 investment firms provided asset and wealth management services. Roughly a quarter had non-EU foreign ownership, mainly from Switzerland, the United States and Monaco, and none had a beneficial owner or parent from an in-scope country. The annual Financial Crime Survey identified only two firms holding relationships linked to in-scope countries, fewer than 50 relationships in total, and the report separately records one client involved in activities related to dual-use items in 2023. On distribution, the report points to the onboarding model: a significant amount of customer due diligence was performed by a third-party introducer or by a third party under outsourcing or agency arrangements, while the screening itself stayed with the supervised firm.

Fund investors are a point where screening duties can be split across entities. Article 39(1a) of CSSF Regulation No 12-02 requires the professional to identify the States, persons, entities and groups subject to restrictive measures in financial matters “with respect to the assets it manages” and to ensure the funds will not be made available to them. The reprimands the CSSF issued in 2024 to two credit institutions, for deficiencies identified in 2022 and 2023, included a professional acting as transfer agent for traditional and alternative funds that screened investors initially but then, for a number of months, ran no ongoing screening of several investors against the persons listed in Annex I of Regulation (EU) No 269/2014. The gap covered parties related to investors as well, such as beneficial owners and representatives of legal entities. The CSSF treated it as a breach of, among other provisions, Article 33(1) and (3) of CSSF Regulation No 12-02.

Payment, e-money and crypto firms: volume and online onboarding

The MVTS deep dive counts 29 licensed payment and e-money institutions, including four branches of institutions from other Member States, which processed 4 billion inflow transactions and 1.07 billion outflow transactions in 2023. Flows to and from non-EU countries made up 29.72% of consolidated flows in 2023. No entity had a beneficial owner or parent from an in-scope country, and the report found no evidence of hawala and similar service providers operating in Luxembourg. What keeps the inherent rating at Medium is volume, client numbers that grew after 2020 with new market entrants, and online distribution, which international guidance treats as higher risk. At the end of 2023, two payment institutions and one e-money institution were also registered as VASPs.

The e-money case in the report shows where a daily screen can still leave a gap. In a 2021 on-site inspection, the CSSF found that the daily name screening of an e-money institution left out a significant number of its active and blocked clients. The CSSF classified the absence of screening for those client groups as a severe breach, which triggered a sanctioning procedure. Once the missing clients were added to the screened database, the institution got hits that it reported to the CRF; the sanctions-list hits among them related to lists other than UN, EU or Luxembourg measures.

The VASP figures describe a population that has since changed legal regime. Eleven VASPs were registered at the end of 2023, with one entity dominating the market. In 2023, 19.7 million virtual asset transactions were exchanged and 1.3 million transfers executed, 99% of clients were natural persons, 99% resided in the EEA, the UK or Switzerland, and there were no deposits from or transfers to the DPRK or Iran. Under Article 24-1 of the Law of 12 November 2004, VASPs registered at 30 December 2024 stayed on the CSSF register until 1 July 2026, or until authorisation was granted or refused under Article 63 of Regulation (EU) 2023/1114 (MiCA), whichever came first. My working assumption is that a crypto-asset service provider now authorised under MiCA can use the VASP row as a reference point, while recording that it was measured on the pre-MiCA market.

Specialised PFS: trust and company services drive the score

Of the 100 specialised PFS supervised by the CSSF in 2023, 85 performed trust and company service provider (TCSP) activities, and the five largest by revenue held a 40% market share. International guidance treats TCSP services as higher risk because designated persons can use corporate vehicles to hide their link to a transaction. Direct exposure is small: according to the sector’s latest annual AML/CFT questionnaires, revenue from in-scope countries is close to zero, and only a handful of firms reported a very small number of clients dealing in dual-use goods. The VRA attaches a caveat that matters for onboarding design. Those figures cover direct client exposure only, and inadvertent exposure through front and shell companies remains possible.

Distribution is the other pressure point: some firms onboarded new clients through remote channels or used third parties to make first contact. Where a banking group performs KYC centrally, the CSSF requires it to be reviewed and accepted locally by the Luxembourg PFS.

The database behind the screen is where one specialised PFS failed. In 2018 the CSSF found an incomplete client database during supervision of the firm and sent an observation letter. Six months later the firm was migrating to a new database and screening two databases against TFS lists, and neither was complete. The CSSF sent an injunction letter giving it one month to complete the new database.

What CSSF inspections found in sanctions screening controls

Sanctions screening controls are part of every full-scope AML/CFT on-site inspection the CSSF runs, with no differentiation by sector. According to the VRA, the most common TFS findings are deficiencies in internal screening procedures, databases or tools that were not updated, parts of the database left unscreened, insufficient screening frequency, and IT problems with the interface between the screening tool and internal systems. The report also records that the maturity of alert investigations is lower for TFS than for money laundering, particularly for PF and at smaller professionals without a fully automated investigation process, and that the CSSF has observed a general trend towards daily name screening, especially at large firms.

Two bank cases turned those findings into published fines. In a September 2019 on-site inspection, the CSSF found that a bank’s procedures set name screening at twice a month, triggered manually, so no control ran immediately when a new sanctions list was published, and human error meant even the twice-monthly frequency was missed. No late filing resulted, but the CSSF treated the weakness as severe and, together with other AML/CFT deficiencies, imposed a pecuniary sanction and published it by name; the bank moved to a daily automated control. In a 2020 inspection, the CSSF found a bank whose screening ran daily against lists that were updated irregularly and had not been updated at all for a one-year period. That case also ended in a published pecuniary sanction, and the bank added a daily control to keep the lists in its screening system current.

A daily run against a stale list fails the same test as a twice-monthly run against a current one. Article 33(3) of CSSF Regulation No 12-02 requires that, after the adoption or update of the official lists, the internal system used for the control, or the one made available by an external service provider, is adapted without delay. In my reading, the auditable evidence for that requirement is the elapsed time between each list publication and its load into the tool.

Survey answers carry consequences too. After the 2020 Financial Crime Survey, banks that had not reported daily name screening or ad hoc list updates were contacted and several received injunction letters; all of them later confirmed daily screening or ad hoc screening on publication of new lists. In January 2023 the CSSF sent observation letters to investment firms whose 2021 answers on screening frequency looked inadequate, followed by injunction letters where the explanations were unsatisfactory. Off-site, the CSSF reviews the statutory auditor’s report, the AML/CFT compliance function report, the internal audit report and the internal control report for deficiencies in name matching and transaction screening.

Freeze first, finish the investigation later: the September 2023 letter

On 6 September 2023 the CSSF wrote to a number of banks to restate what “without delay” means for alerts after each new adoption or amendment of UN, EU or national TFS lists. The letter anchored the expectation in Article 6 of the Law of 19 December 2020, the Grand-Ducal Regulation of 14 November 2022, and Articles 33(1), (2) and (3) and 39(1) and (1a) of CSSF Regulation No 12-02, and it set three process expectations:

  • daily name screening and transaction screening alerts are handled without delay, at least at the first level of control;
  • the related restrictive measures, such as the freezing of the customer’s accounts, are also executed without delay, even if the alert needs further investigation taking longer than 24 hours, which may take up to several days, to confirm the suspicion;
  • the Ministry of Finance is notified without delay, always with reference to a legal basis, with a copy to the CSSF at the same time, even if the full investigation is not finalised.

The letter predates Circular CSSF 25/896. Under Guidelines EBA/GL/2024/14, which the CSSF applies to credit institutions, investment firms, payment institutions and e-money institutions from 30 December 2025, firms’ procedures should start investigating every potential match without delay, and a true positive match should trigger follow-up action including immediate rejection, suspension or freezing, and reporting to the competent national authorities.

The Grand-Ducal Regulation of 14 November 2022 is short and absolute on timing. Its Article 1 requires the natural and legal persons obliged to apply the restrictive measures of the Law of 19 December 2020 to do so without delay and without prior notification, and its Article 2 requires them to inform the Minister of Finance of each restrictive measure taken, including attempted transactions, without delay. The Ministry of Finance’s published guidance distinguishes an unresolved name match from an established listing. In a homonym situation, transactions are suspended while additional identifiers are gathered and, where doubt remains, the Ministry is contacted; once the operator becomes aware that the person is listed, the required freeze must be applied without delay.

The 2024 reprimands apply the same standard after the event. Beyond the transfer agent finding, the deficiencies listed for the two credit institutions included late implementation of restrictive measures on two accounts of one client covered by Regulation (EU) No 269/2014, on which bank charges were automatically debited and interest credited each month although no designated person accessed the funds; late information to the Ministry of Finance; and late freezing and late reporting for a person listed in Annex I of that Regulation. The CSSF cited Articles 2 and 7 of Regulation (EU) No 269/2014, Article 6(1) of the Law of 19 December 2020, Articles 1 and 2 of the Grand-Ducal Regulation of 14 November 2022 and Article 33(2) of CSSF Regulation No 12-02.

Ministry first, CSSF in copy: routing a true match

The reporting chain for a true match runs to the Ministry of Finance. Article 6(1) of the Law of 19 December 2020 requires persons applying restrictive measures to inform the Minister responsible for finance of each measure taken, including attempted transactions, and Article 33(2) of CSSF Regulation No 12-02 requires a copy of that communication to go to the CSSF at the same time. The Minister is also the authority that can exceptionally grant derogating authorisations, where the underlying UN resolutions and EU acts allow them.

The CRF enters on a separate trigger. A report to the CRF is required where the professional knows, suspects or has reasonable grounds to suspect that money laundering, terrorist financing or an associated predicate offence is being committed, has been committed or attempted. Infringement of Article 10 of the Law of 19 December 2020 constitutes an associated predicate offence for money laundering: expressly listed as such from July 2022, and still a predicate offence today because the Law of 12 December 2025 replaced the Penal Code’s fixed list with a broader rule that treats any crime or misdemeanour as a predicate offence. That offence carries imprisonment of eight days to five years and a fine of EUR 12,500 to EUR 5,000,000, or one of the two, and the fine can rise to four times the amount of the offence where it produced substantial financial gain.

The VRA adds that a designation on its own does not amount to a suspicion, though it should trigger a careful review of the whole business relationship. The CSSF’s Banking Department found cases in earlier years where reports went to the CRF instead of the Ministry as the first instance, and followed up with the banks concerned. For the CRF side of the process, see our walkthrough of the goAML reporting workflow in Luxembourg.

A freeze also creates a recurring return. Operators holding frozen assets, whatever their sector, provide the Ministry with a quarterly inventory of their status, and since the second quarter of 2021 the Ministry has used a standard Excel template. The excerpt reproduced in the VRA shows columns for the legal basis (EU regulation, UN resolution or both), the amount frozen in the original currency and in euro, the date of freezing, and an explanation of any change in value since the previous quarter, such as exchange rates or fees charged under an authorisation. The Ministry consolidates the reports and shares the information with the European Commission. Frozen assets linked to in-scope countries, as reported to the Ministry, stood at EUR 2.95 billion in 2018, peaked at EUR 4.92 billion in 2022 and were EUR 4.44 billion in 2023.

Where the VRA enters the business-wide risk assessment

The legal hook is the risk assessment duty. Article 2-2(2) of the Law of 12 November 2004 requires professionals to incorporate risk information from the national and supranational risk assessments, or communicated by supervisory authorities, and to document the assessment, keep it up to date and make it available to supervisors. Article 4(1) of CSSF Regulation No 12-02 lists the sources a professional incorporates into its risk management procedures, including the national risk assessment, sub-sector risk assessments and “the relating CSSF publications”. The VRA carries none of those labels exactly. My reading is that the CSSF communiqué of 24 September 2026 brings it within risk information communicated by the supervisory authority, which makes its absence from a documented assessment hard to explain.

The substantive edits are narrower than a rewrite:

  1. Record the firm’s sub-sector row, inherent and residual, with the drivers the report names, and note where the firm’s own profile differs, for example a retail bank that also runs correspondent accounts.
  2. Split TFS risk into a PF line and a TF line. A PF line built on the report would reflect the DPRK and Iran typologies it describes, including networks of front and shell companies, cyberattacks used to raise funds and evasion at sea through ship-to-ship transfers, mapped to the products that could carry them.
  3. Carry the legal-person ratings into customer risk scoring, with fiducies, foreign trusts and non-profit structures active abroad at Very High and sociétés commerciales at High.
  4. Tie the control assessment to the failure patterns in the case files: screening frequency, list currency, completeness of the screened population, alert ageing, and the time from match to freeze to Ministry notification.

CSSF Regulation No 12-02 already fixes the documentation around those controls. Article 38(2), point 17 requires AML/CFT policies and procedures to include the procedures with respect to financial restrictive measures. Article 39(2) requires a complete and up-to-date customer database, subject to a four-eyes principle where a person does the encoding, covering customers, persons acting on their behalf, initiators and beneficial owners, and automated unless the professional can prove its volumes do not require it. Article 39(3) requires the identification searches to be documented, including where they return no positive result.

What changes next: AMLR Article 10, bill 8579 and the 2026 data collection

Once the AMLR applies, Article 10(1) of Regulation (EU) 2024/1624 requires obliged entities to identify and assess their money laundering and terrorist financing risks “as well as the risks of non-implementation and evasion of targeted financial sanctions”, taking into account at least the findings of the national risk assessments “as well as of any relevant sector-specific risk assessment carried out by the Member States”. The CSSF’s consolidated text of Article 2-2 of the Law of 12 November 2004 speaks of money laundering and terrorist financing risks and does not name TFS risk as a separate component. In my reading, the VRA is the kind of sector-specific assessment point (c) of Article 10(1) describes, so a TFS section built against it now already has the shape the AMLR names. Our overview of what the AMLR changes in Luxembourg covers the wider switch.

The criminal side is moving as well. Bill No 8579, which transposes certain provisions of Directive (EU) 2024/1226 on criminal offences and penalties for the violation of Union restrictive measures and amends the Law of 19 December 2020 among other texts, was still before the Chamber of Deputies’ Justice Committee at the time of writing, with parliamentary amendments filed on 10 July 2026. The directive’s transposition deadline was 20 May 2025.

The data that fed the VRA is changing shape too. Several of the CSSF data points in the report come from the annual Financial Crime Survey. For 2026, according to its circular letter of 12 February 2026, the CSSF deployed AMLA’s data collection templates instead of its usual annual Questionnaire on Financial Crime, except for specialised PFS, which completed the usual CSSF questionnaire, including its questions on targeted financial sanctions measures, by 3 April 2026. The same letter says an ad hoc questionnaire may still be requested later in the year to collect essential data points, such as those required for FATF, that the AMLA questionnaire does not cover. The background is in our note on the CSSF AML/CFT standardised data collection for 2026.

Frequently Asked Questions

Our Luxembourg branch relies on the parent’s group screening engine. Do the CSSF screening rules still apply to the branch?

Yes. CSSF Regulation No 12-02 applies to professionals supervised, authorised or registered by the CSSF, including Luxembourg branches of foreign professionals notified to the CSSF, and the Law of 19 December 2020 applies restrictive measures to branches in Luxembourg of foreign legal persons. Article 33(3) of the Regulation expressly covers a screening system made available by an external service provider, which must be adapted without delay after list updates, and under Article 37(3) responsibility stays with the professional using a third-party delegate. In my reading, the group tool’s list-update timing and its coverage of the branch’s customers therefore belong in the branch’s own control file.

A name matches an OFAC listing but no UN, EU or Luxembourg measure. Does it go to the Ministry of Finance?

On the text of the Law of 19 December 2020, the freeze and Ministry notification duties attach to restrictive measures adopted under UN Security Council resolutions, EU acts or a Luxembourg grand-ducal regulation. The VRA records that the CRF also receives reports based on lists drawn up by foreign jurisdictions that may not be fully applicable in Luxembourg, such as US OFAC lists. An OFAC-only listing does not, solely by virtue of that listing, trigger the Luxembourg freeze-and-notify regime under the Law of 19 December 2020. The CSSF’s AML/CFT FAQ adds that a professional may nevertheless be required, depending on its legal situation, to consult lists published by foreign authorities such as the US OFAC lists, that the analysis and application of any such measures then rests with the professional, and that it must separately assess whether the facts trigger an AML/CFT suspicious-transaction reporting obligation.

We are confident a hit is a homonym. Do we still contact the Ministry?

The VRA, citing the Ministry of Finance’s guidelines, says that where the identifiers gathered clearly show the two individuals are different people, the Ministry need not be contacted. In case of any doubt, the Ministry should still be contacted, and operators are expected to suspend transactions on the account until the situation is clarified. Documenting the discounting rationale, in line with the Article 39(3) duty in CSSF Regulation No 12-02 to document identification searches, is what shows the doubt was resolved.

Our sub-sector is rated Low. Can we screen weekly instead of daily?

A Low VRA sector rating does not by itself authorise weekly-only screening. Since 30 December 2025, Circular CSSF 25/896 applies the EBA restrictive-measures guidelines. For PSPs and CASPs, EBA/GL/2024/15 requires regular screening of the entire customer database, with the regular frequency determined from the restrictive-measures exposure assessment, and additional screening on specified trigger events including new or changed designations and new restrictive measures. Other institutions within the scope of Circular CSSF 25/896 must maintain controls proportionate to their restrictive-measures exposure while ensuring that applicable restrictive measures are implemented without delay.

A client we froze has been de-listed. What happens to the freeze?

The VRA states that when supervised professionals notice a de-listing as part of their ongoing due diligence, they should also act to de-freeze the funds and assets. The Ministry of Finance publishes de-listing decisions in the Official Gazette, on its website and through its newsletter, and the CSSF’s 2020 reminder to banks covered updating screening tools without delay for de-listed as well as newly designated names.

We are registrar and transfer agent for funds whose manager is another entity. Whose investor screening obligation is it?

Both sides keep obligations. Article 37(4) of CSSF Regulation No 12-02 provides that where a registrar and transfer agent acts on behalf of an investment fund, the fund’s board and the investment fund manager that outsource tasks to it remain liable, and that being treated as part of the fund or manager under the outsourcing contract does not exempt the agent from its own AML/CFT obligations. The outsourcing contract is where the split of screening tasks, and the manager’s access to the agent’s results, is written down. Ministry reporting stays with each party: the CSSF’s FAQ on international financial sanctions (Question 13) says that where a transfer and register agent, a depositary bank and an intermediary are contractually linked around the same fund, each must itself report a restrictive measure to the Ministry of Finance, with a simultaneous copy to the CSSF, even if another party in the chain has already informed the authorities.

Key Takeaways

  • File the VRA as a dated source in the business-wide risk assessment, with the firm’s sub-sector row and the drivers the report names.
  • Trade finance desks: document the trading-route and goods analysis behind each file, the formalisation the CSSF asked for after its 2023 trade finance inspection.
  • Pull a year of list-load and screening-run logs and measure publication-to-load time; a bank screening daily against stale lists still drew a published fine.
  • Reconcile the screened population against every client status, including blocked clients and fund investors where the firm acts as transfer agent.
  • Time-stamp the alert, any transaction suspension, the true-match decision, the freeze and the Ministry notification separately; unresolved homonym cases require transaction suspension while the identity is clarified, while the freeze applies without delay once the assets are identified as subject to an applicable restrictive measure.
  • Send true matches to the Ministry of Finance with a simultaneous copy to the CSSF, and to the CRF only on suspicion or an Article 10 failure.
  • Keep capacity in late 2026 for a possible ad hoc CSSF questionnaire on FATF data points the AMLA templates did not collect.

Sources and References

  • CSSF, communiqué “Luxembourg finalises its first vertical risk assessment on international financial sanctions related to terrorist financing and to proliferation financing” (24 September 2026): cssf.lu
  • Ministry of Finance, press release on the first vertical risk assessment on international financial sanctions (21 September 2026): mfin.gouvernement.lu
  • Ministry of Finance, “PF and TF TFS VRA: Luxembourg’s Vertical Risk Assessment into Proliferation Financing and Terrorist Financing Targeted Financial Sanctions”, observation period 2018-2023 (June 2026): PDF
  • Law of 19 December 2020 on the implementation of restrictive measures in financial matters: Legilux; CSSF consolidated English text: PDF
  • Grand-Ducal Regulation of 14 November 2022 specifying the Law of 19 December 2020 (Mémorial A No 561): Legilux
  • Law of 12 November 2004 on the fight against money laundering and terrorist financing, CSSF consolidated English text: PDF
  • CSSF Regulation No 12-02 of 14 December 2012 on the fight against money laundering and terrorist financing, as amended by CSSF Regulation No 20-05: PDF
  • Circular CSSF 22/822 on FATF statements concerning high-risk jurisdictions and jurisdictions under increased monitoring: cssf.lu
  • Circular CSSF 25/896, “Adoption of the EBA guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)” (18 August 2025, applicable from 30 December 2025), annexing Guidelines EBA/GL/2024/14 and EBA/GL/2024/15: PDF
  • Ministry of Finance, “Guidelines relating to the implementation of financial restrictive measures (sanctions) against third countries, entities or individuals”: PDF
  • CSSF, “Frequently asked questions regarding the fight against money laundering and counter terrorist financing (AML/CTF) for individuals/investors”, Question 9 (modified 4 March 2021): PDF
  • CSSF, “Frequently asked questions regarding International Financial Sanctions”, Question 13 (published 30 September 2025; FAQ version of 3 November 2025): PDF
  • CSSF circular letter “AML/CFT standardised data collection exercise taking place in 2026” (12 February 2026): PDF
  • Regulation (EU) 2024/1624 (AMLR), Articles 10 and 90: EUR-Lex
  • Council Regulation (EU) No 269/2014, consolidated text (check EUR-Lex for the version current on the reader’s access date): EUR-Lex
  • Directive (EU) 2024/1226 on the definition of criminal offences and penalties for the violation of Union restrictive measures: EUR-Lex
  • Chamber of Deputies, bill No 8579 (parliamentary file): chd.lu

Before the AMLR switch: what already applies

For firms within the scope of Circular CSSF 25/896, the current framework already requires a restrictive-measures exposure assessment, with review at least annually and on specified trigger events; the VRA is a relevant input to that assessment where applicable. Separately, professionals within the scope of Article 2-2(2) of the Law of 12 November 2004 must incorporate relevant risk information from national and supranational risk assessments or communicated by supervisory authorities into their documented risk assessment. AMLR Article 10 will expressly add the risks of non-implementation and evasion of targeted financial sanctions when it applies from 10 July 2027.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • DORA Register of Information – A Practical Guide for Financial Entities

    Updated July 2026In this guideLegal Basis and PurposeWho Needs to Maintain the RegisterTemplate StructureThe 19 ICT Service TypesCritical or Important Functions: The Data Depth DriverContractual Arrangement Reference NumbersSubmission Process and CSSF DeadlinesCommon Errors and How to Avoid ThemOngoing Maintenance ObligationsHow the Register Feeds the CTPP Oversight FrameworkEBA ICT Risk Report: Supervisory ContextFrequently Asked QuestionsPractical Implementation…

  • CSSF AML/CFT Sanction: Enforcement Lessons From the March 2026 Fine

    Updated July 2026In this guideWhat the CSSF AML/CFT sanction actually coveredLate and incomplete suspicious activity reportsThe client-portfolio takeover trapName screening, sanctions and PEP alert backlogsOutsourced screening and the four-eyes gapDatabase completeness is an AML control, not IT housekeepingHow supervisors surface these gaps before an inspectionFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesReading the sanction as a…

  • FATF Travel Rule Implementation: The Enforcement Gap

    Updated September 2026In this guideThe dates that anchor this updateWhat the seventh targeted update actually measuresWhere FATF Travel Rule implementation now standsThe distance between a rule and a working controlOffshore VASPs and the edge of the licensing perimeterStablecoins, unhosted wallets and the P2P edgeHow the EU sits against the FATF baselineWhat compliance and reporting teams…

  • CSSF MiFID II Notification Templates: The 13 July 2026 Filing Set

    On 13 July 2026 the CSSF published five standardised XLSX notification forms on its Markets in Financial Instruments (MiFID II/MiFIR) page, covering algorithmic trading, direct electronic access, systematic internaliser status, designated publishing entity status and commodity derivatives. For algorithmic-trading and DEA notifications, the workbook replaces the Q&A-table format referenced in the CSSF’s communication of 26…

  • Pillar 3 Disclosure Requirements for Luxembourg Banks – A Practical Guide

    Updated July 2026In this guideWhat Pillar 3 Is and Why It ExistsLegal BasisWho Must DiscloseWhat Gets Disclosed: The Template FrameworkDisclosure Frequencies at a GlanceFormat and Publication RequirementsESG Disclosures Under Article 449aLuxembourg-Specific ImplementationCommon Errors and Supervisory FindingsFrequently Asked QuestionsKey TakeawaysRelated ArticlesSources and ReferencesCOREP and FINREP go to the supervisor. Pillar 3 goes to the public. That…