Legilux ¦ Law of 22 July 2026: Luxembourg’s New Fraud Signal Regime

Legilux ¦ Law of 22 July 2026: Luxembourg’s New Fraud Signal Regime

Luxembourg has now given the financial intelligence unit (FIU), the Cellule de Renseignement Financier (CRF), a formal legal basis to share fraud-related signals with selected professionals in the financial sector. The new law of 22 July 2026 inserts article 74-4bis into the law on judicial organisation and creates article 5-1 in the anti-money laundering law. Together, these provisions establish a structured channel for sharing account-level fraud intelligence where the risk is serious enough to justify intervention.

This is not a broad public warning system. It is a targeted mechanism for professionals who actively ask to receive the information. The objective is narrower and more operational: to help prevent the reuse of accounts tied to major fraud patterns, and to strengthen anti-money laundering controls around the proceeds of those offences.

What the financial intelligence unit may share

Under article 74-4bis, the financial intelligence unit may signal typologies and information presenting a significant fraud risk to professionals covered by article 2(1), points 1 and 20, of the anti-money laundering law. In practical terms, this covers banks and the relevant payment and virtual asset service professionals that fall within that scope.

The law is precise about the kind of information that can be shared. It concerns the numbers of accounts that have come to the attention of the financial intelligence unit in the exercise of its legal functions and that present a significant fraud risk. The signal also identifies the fraud typology in which those accounts were used.

That is an important limitation. The law does not create a general blacklist. It does not authorise open-ended circulation of all suspicious accounts. It does not transform every fraud-related file into a sector-wide alert. The signal must be tied to a serious fraud typology and to accounts that have been specifically identified in that context.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Luxembourg has introduced a targeted legal framework allowing the financial intelligence unit to share significant fraud-related account signals with selected professionals through a secure channel. The mechanism is limited to serious fraud typologies and is designed to help institutions detect and interrupt suspicious payment flows earlier.

The law also places clear obligations on the receiving professionals: they may use the information only for anti-money laundering purposes, may not disclose it to clients or third parties, and must delete it within six months. Its effectiveness will depend on disciplined use, strong internal controls, and regular feedback between the public and private sectors."

The fraud types covered

The law defines “typologies presenting a significant fraud risk” as frauds and attempted frauds under the Criminal Code, as well as the laundering of the proceeds of those offences, when they are carried out on a large scale against unidentified victims or use social engineering techniques aimed at specific victims.

That wording captures the fraud patterns that matter most in modern financial crime practice. It includes phishing campaigns with broad victim pools, president fraud, business email compromise, false payment order schemes, and similar methods that combine speed, impersonation, and rapid movement of funds. It also captures the laundering side of the problem, which is just as important as the initial deception.

The inclusion of laundering of the proceeds is especially relevant. Fraud today is rarely confined to the initial transfer. Once the money leaves the victim, it often passes through several accounts or payment instruments, including accounts opened specifically to receive and disperse stolen funds. The law is designed to give institutions a better chance of interrupting that chain.

How access works

The signal is only sent to professionals who have requested it through a secure channel. Unless they expressly withdraw, that request applies to all signals transmitted by the financial intelligence unit.

That structure matters because it avoids indiscriminate distribution. It also means the receiving institution has made a deliberate choice to be part of the mechanism and must therefore be ready to handle the information properly.

The law requires that all transmission of signals, and all exchanges between the professionals and the financial intelligence unit, occur exclusively through a secure channel. This is not a decorative formality. It is the legal backbone of the system. It ensures traceability, confidentiality, and a defensible audit trail.

What the professionals may do with the information

Article 5-1 is equally clear about the use of the signals. Professionals may use them only in the context of anti-money laundering, the associated predicate offences, and terrorist financing. The use is under their sole responsibility.

That responsibility clause is central. The signal is not an order to block a transaction, not a mandatory instruction to file a suspicious activity report, and not a legal determination that an account holder is guilty. It is a control input. The professional must decide how to act, based on its own risk framework and the wider circumstances of the case.

In practice, the signal may support a stronger customer risk assessment, a transaction review, a payment decision, or an internal escalation. It may also help determine whether there is enough basis to file a report to the financial intelligence unit. But the law does not turn the signal into an automatic trigger. That choice is deliberately left to the professional.

No disclosure to clients or third parties

The law also prohibits revealing the signal to the client concerned or to any third party. That confidentiality rule is crucial. If a fraudster learns that an account has been flagged, the account can be abandoned and the funds moved elsewhere before any preventive measure takes effect.

The secrecy rule also protects the broader intelligence value of the mechanism. If market participants or clients could see the signals, the system would quickly lose credibility and operational usefulness. The prohibition therefore supports both enforcement and effectiveness.

The six-month deletion rule

Professionals must delete all information received under article 74-4bis paragraph 4, first subparagraph, within six months of receipt. This is a strict retention limit, and it is one of the most practical aspects of the law.

For compliance teams, this will require a clear lifecycle process. Institutions will need to track when each signal was received, how it was used, and when it must be deleted. That means internal controls, logging, access limitation, and retention logic will all need to work together.

The six-month limit also signals that the legislature sees this information as time-sensitive. Fraud intelligence loses value fast. An account used in an active scam may be highly relevant for a few days or weeks, but much less so after the trail has gone cold. The deletion rule reflects that reality.

Feedback is built into the model

The financial intelligence unit must organise meetings with participating professionals at least every six months, especially to discuss the relevance of the signals sent. It must adapt future signals based on the feedback received.

This is one of the strongest features of the law. It makes the mechanism iterative rather than static. That is essential in fraud prevention, where tactics shift quickly and the quality of the intelligence matters as much as the existence of the channel.

Regular feedback should help identify whether the signals are useful, whether the typologies are well chosen, whether false positives are a problem, and whether the institutions are seeing the same patterns in their own files. It should also help the financial intelligence unit refine which accounts and typologies deserve inclusion.

Why this law matters for Luxembourg’s financial crime strategy

The law reflects a broader shift toward operational cooperation between the public sector and regulated professionals. Fraud is too fast-moving to be handled only through traditional reporting after the fact. By the time a suspicious activity report is filed, the victim’s funds may already be gone. A targeted signal delivered earlier can make the difference between loss and interception.

That is especially important in Luxembourg, where the risk landscape includes cross-border account use, fast payment rails, and sophisticated fraud schemes that often span several jurisdictions. The law does not solve all of that, but it gives the financial intelligence unit a clearer role in prevention, not just detection and post-event analysis.

It also places real responsibility on the private sector. Institutions that opt in will need to integrate the signals into their controls, understand their limits, and handle them in a way that is both useful and legally compliant. The law gives them a tool. It does not remove the need for judgment.

The bottom line

Luxembourg has taken a practical step toward better fraud prevention. The new framework allows the financial intelligence unit to share account-based fraud signals with selected professionals through a secure channel, but only for significant fraud typologies and only within a tightly controlled legal structure.

The model is selective, confidential, and time-limited. It is also deliberately dependent on professional judgment. That makes it more demanding than a simple blacklist system, but also more defensible and more in line with modern anti-money laundering practice.

Its success will depend on whether institutions use the signals consistently, whether the information is accurate enough to act on, and whether the feedback loop improves the quality of future signals. If those conditions are met, the law could become a useful part of Luxembourg’s anti-fraud toolkit.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • Journal officiel (Mèmorial A) ¦ Loi du 22 juillet 2026 (Law of 22 July 2026) ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.