CRF ¦ Guidelines on the Cooperation with the FIU

CRF ¦ Guidelines on the Cooperation with the FIU

Luxembourg’s Financial Intelligence Unit has updated its expectations for cooperation by professionals subject to the amended anti-money laundering and counter-terrorist financing framework. The guidance places particular emphasis on the early identification of suspicious activity, the relevance of the underlying predicate offense, the quality of suspicious operations reports and the speed of responses to information requests.

For compliance functions, the central message is clear: reporting is not dependent on proving a criminal offense, identifying the precise legal classification of the conduct or reaching a monetary threshold. A reasonable, fact-based suspicion is sufficient, provided it results from a meaningful assessment of the available information.

The all-crime approach changes the predicate offense analysis

Since the entry into force of Luxembourg’s Law of 12 December 2025, the predicate offense framework has moved to an all-crime approach. Any crime or misdemeanor, if established, may constitute a predicate offense for money laundering purposes.

This significantly broadens the range of conduct relevant to transaction monitoring and suspicious activity investigations. Compliance teams can no longer approach predicate offense risk through a limited catalogue of predefined offenses. Potential proceeds may originate from any criminal or correctional offense, including conduct that is not traditionally associated with financial crime controls.

The reporting obligation does not require the obliged entity to determine which specific predicate offense has been committed. Nor must it establish that the predicate offense actually occurred. The relevant question is whether the available circumstances make money laundering, a predicate offense or terrorist financing a plausible hypothesis.

The underlying conduct may also have occurred abroad. Luxembourg’s framework recognizes money laundering linked to a predicate offense committed outside the country, and the same person may be responsible for both the predicate offense and the subsequent laundering activity.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Luxembourg’s updated FIU expectations reinforce that suspicious activity must be reported promptly whenever facts support a reasonable suspicion of money laundering, any criminal predicate offense or terrorist financing. No proof of the offense, precise legal classification or minimum transaction value is required, but reports must be clear, well-supported and based on documented analysis.

Obliged entities must also respond rapidly to FIU information requests, comply with freezing orders and maintain strict confidentiality. With criminal fines of up to €5 million for serious breaches, effective goAML procedures, escalation controls and careful management of post-report customer relationships are essential."

Suspicion is a risk-based conclusion, not a finding of guilt

A suspicious operation is one that an obliged entity knows, suspects or has reasonable grounds to suspect is connected with money laundering, an associated predicate offense or terrorist financing. The suspicion may concern the customer, a related person or the operation itself.

This standard is deliberately lower than the evidentiary threshold required for criminal prosecution. A reporting entity is not expected to establish proof or produce a complete reconstruction of the criminal conduct. It must, however, conduct a proper assessment. A mere feeling of uncertainty, without supporting facts or analysis, is not enough.

Suspicion may arise from a combination of factors that appear insignificant in isolation. Relevant considerations include the customer’s identity and profile, the development of the relationship, the customer’s financial history and business activities, the source and destination of funds, the purpose and nature of the transaction, the method used and the relationship between multiple transactions.

The assessment must be contextual. A transaction that is unusual for one customer may be ordinary for another. Industry practice, the customer’s stated business model and the information obtained through customer due diligence all affect the analysis. The key issue is whether the activity is consistent with the customer’s known profile and whether a reasonable explanation exists.

There is no minimum reporting threshold. Suspicious activity must be reported regardless of value, including attempted transactions.

Attempts can trigger the reporting obligation

The reporting duty extends to attempted money laundering, attempted predicate offenses and attempted terrorist financing. An attempt may arise where a prospective or existing customer has taken concrete steps to implement the activity but has failed because of circumstances outside the customer’s control, including intervention arising from the obliged entity’s due diligence.

A general request for information about the terms of a transaction is not, by itself, an attempt. The customer must have moved beyond a preliminary inquiry and begun implementing the arrangement. Examples may include entering into business negotiations, issuing a transfer instruction or establishing a legal structure.

This distinction matters operationally. Compliance teams should record the point at which conduct moved from inquiry to execution, particularly where a transaction was stopped because of customer due diligence concerns. A failed transaction may still provide important evidence of attempted financial crime and should not be excluded from reporting merely because no funds ultimately moved.

Reporting must be prompt and supported

The obligation to report arises as soon as the obliged entity concludes that a residual, reasonable suspicion remains. The report must be submitted promptly and on the entity’s own initiative.

Before reporting, professionals must refrain from executing a transaction they know, suspect or have reasonable grounds to suspect is linked to money laundering, a predicate offense or terrorist financing. This does not mean that every unusual transaction must be blocked indefinitely. It means that the transaction must not be executed before the required report has been made and any specific instruction from the FIU has been followed.

Reports must include the information and documents that led to the suspicion. The FIU expects submissions to be clear, accurate, complete and current. They should identify the people and entities involved, describe the relevant facts precisely and explain why the activity is inconsistent with the available customer information or otherwise raises concern.

A report should reflect genuine preliminary analysis rather than a collection of unexplained alerts. Transaction data, account information, corporate records, communications, due diligence material and relevant external information should be included where they support the suspicion or assist the FIU’s analysis.

Predicate offense indicators should be made explicit

A strong suspicious operations report should distinguish between the observed financial activity and the possible criminal source of the funds. The reporting entity does not need to make a definitive legal determination, but it should identify the suspected typology or possible predicate offense where the facts support doing so.

This is particularly important under the all-crime approach. A report may involve suspected fraud, corruption, drug trafficking, organized crime, tax-related crime, theft, cybercrime or another criminal offense. The report should explain the factual basis for the concern, rather than relying on a generic reference to “money laundering.”

The FIU’s indicator catalogues are intended to support this process. They organize indicators by transactional behavior, suspected predicate offenses, typologies, sectors, products and contextual factors. Their use is not mandatory, but relevant indicators can improve consistency, clarify the rationale for the report and help the FIU identify recurring patterns across institutions.

GoAML registration is an operational requirement

Suspicious operations reports must be submitted through the FIU’s goAML Web platform. Obliged entities must register in advance as reporting entities and designate at least one compliance officer. They must also maintain functional access and ensure that authorized users are properly registered.

The platform supports both online filing and XML uploads. Online forms are generally suited to reports involving a limited number of transactions. Entities that file regularly or submit reports containing extensive transaction data are encouraged to develop systems that can export the relevant information directly into an XML file.

The technical quality of a filing is part of its overall effectiveness. Required fields must be completed correctly, transaction details must be structured accurately and supporting documents must be attached in a form that enables the FIU to review the facts efficiently.

Information requests require rapid escalation

The FIU may request information even where no suspicious operations report has been filed. Obliged entities must provide all requested information and supporting documents without delay.

The applicable response periods are five business days for standard requests and 24 hours for highly urgent requests. In specific and duly justified cases, the FIU may impose a period of less than 24 hours.

These deadlines require firms to treat FIU communications as time-critical matters. Relevant procedures should define who monitors the goAML message board, who can access requests outside normal working hours, how information is gathered and reviewed, and who has authority to submit the final response.

Responses are made through the requested information activity or transaction report forms on goAML. Firms that have not registered must complete the registration process before they can respond through the platform.

A report does not automatically require the relationship to end

Submitting a suspicious operations report does not, by itself, require termination of the customer relationship. The decision to continue or terminate remains with the reporting entity, which retains responsibility for its business decision.

The position is different where customer due diligence obligations cannot be completed. In that situation, the AML/CFT framework may prevent the entity from establishing or continuing the relationship or carrying out the transaction, and the entity must consider whether a suspicious operations report is appropriate.

Subsequent transactions that are unrelated to the reported activity and do not appear suspicious do not need to be reported solely because an earlier report was filed. If later activity raises a new suspicion, a further report must be submitted promptly.

This requires careful distinction between relationship management and reporting obligations. Commercial decisions should not be presented to the customer as an FIU instruction, and a decision to retain the relationship should not weaken ongoing monitoring.

Freezing orders can cover a wide range of assets

The FIU may issue instructions not to carry out operations relating to a transaction or customer. The concept of a transaction is broad and may include activity on a bank account, assets held in a safe-deposit box, the redemption of a life insurance policy, entries in a fund or sub-fund investor register, or transactions involving virtual asset portfolios.

A freezing order may apply to a specific transaction or to a broader business relationship. It can be general, covering all transactions connected with the relationship, or partial, covering only the operations identified in the order.

The measure is intended to stop activity that may form part of an ongoing money laundering or terrorist financing scheme. It may precede judicial seizure or further analysis by the FIU. In some circumstances, the FIU may permit a transaction to proceed to avoid alerting the customer or compromising an investigation.

An urgent freezing order may be communicated by telephone, but written confirmation must follow within three days. For registered entities, notification is generally made through the goAML message board. The order must be implemented precisely, and a partial order does not necessarily prevent unrelated, non-suspicious transactions from being carried out at the entity’s own responsibility.

Freezing orders affect the relationship as well as the transaction

A business relationship may not be terminated while a freezing order is in force if termination would undermine the effectiveness of the measure. Once the order has been withdrawn, the law does not automatically require the relationship to be terminated.

The FIU may withdraw a freeze in whole or in part at any time when the circumstances no longer justify its continuation. After notification of the withdrawal, the reporting entity may resume the affected transactions at its own responsibility unless the FIU gives different instructions.

Persons with an interest in the affected property and the professional concerned may seek judicial review before the Council Chamber of the Luxembourg District Court. The procedure includes short notification and reporting periods, reflecting the urgency and potential impact of a freezing measure.

No tipping-off remains a criminal exposure

The prohibition on disclosure is comprehensive. Reporting entities must not tell a customer or another unauthorized person that a suspicious operations report has been or will be filed, that information has been provided to the FIU, or that the FIU has requested information.

The same restriction applies to freezing orders unless the FIU has expressly authorized disclosure. In many cases, an order may allow the entity to tell a customer who asks why a transaction was not executed that an FIU freeze is in effect and that legal redress may be available. The entity must not provide a copy of the order unless authorized.

Limited information sharing may be permitted within groups, networks or between relevant professionals in certain cross-border circumstances. Such exchanges are subject to conditions concerning equivalent AML/CFT obligations, professional secrecy, data protection and the purpose for which the information is used.

Internal controls should therefore address not only whether information may be shared, but also the precise wording employees may use with customers, counterparties and other members of staff. Poorly managed communications can expose an institution to criminal liability and compromise the effectiveness of an investigation.

Good-faith cooperation is protected

Professionals, directors and employees benefit from statutory protection when they disclose information to the FIU in good faith in connection with a suspicious operations report or a response to an information request. Such disclosure does not breach contractual restrictions, professional secrecy or other confidentiality obligations, and does not create liability merely because the underlying predicate offense was not specifically known or did not ultimately occur.

Information supplied to the FIU may also not be used against the reporting entity in proceedings concerning a breach of its professional obligations. This protection supports a reporting culture based on responsible escalation rather than certainty of criminal conduct.

The identity of the reporting entity and the individuals involved is generally kept confidential by the FIU. Disclosure may occur where essential to ensure the regularity of proceedings or establish the facts underlying them.

Enforcement consequences are substantial

Failure to submit a required report or respond to an FIU information request may result in a criminal fine ranging from €12,500 to €5 million. The same range of sanctions may apply to disclosure of a suspicious operations report, an FIU information request or an unauthorized freezing order.

Regulatory and self-regulatory bodies also have expanded supervisory and enforcement powers. Deficiencies may therefore lead to consequences beyond the criminal fine, including supervisory measures and professional sanctions.

The practical lesson is that reporting quality, response management and confidentiality controls should be treated as core financial crime controls. Registration on goAML, access monitoring, escalation procedures, evidence preservation and staff training are not administrative details. They are part of the institution’s legal ability to cooperate with the FIU.

The FIU is not a transaction approval authority

The FIU does not approve transactions, confirm their legality or provide case-specific legal advice. An acknowledgment of receipt is not permission to proceed, and the absence of a freezing order does not transfer the business decision to the FIU.

After a report or response has been acknowledged, the obliged entity remains responsible for deciding whether to execute the transaction or continue the relationship, subject to its statutory obligations and any specific FIU instruction.

That division of responsibility is fundamental. The FIU assesses and disseminates financial intelligence, while the reporting entity remains accountable for customer due diligence, transaction decisions, risk management and the quality of its cooperation.

A more disciplined reporting model is required

The updated expectations point toward a reporting model built on three connected disciplines. First, firms must identify the full range of possible criminal sources of funds, including offenses outside traditional money laundering typologies. Second, they must convert customer and transaction data into a documented, fact-based suspicion without waiting for proof. Third, they must communicate that suspicion promptly and clearly through the prescribed channels.

The strongest control frameworks will connect transaction monitoring, investigations, predicate offense analysis, report drafting and post-report relationship management. They will also use FIU feedback to refine alert logic, improve report quality and identify recurring weaknesses.

For Luxembourg obliged entities, effective cooperation is not limited to filing a report. It includes recognizing attempted conduct, preserving the evidence behind the suspicion, meeting accelerated information-request deadlines, executing freezing orders accurately and protecting the confidentiality of every interaction with the FIU.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • Cellule de Renseignement Financier (CRF) ¦ Guidelines on the cooperation with the FIU ¦ Link
  • Cellule de Renseignement Financier (CRF) ¦ Guidelines on the cooperation with the FIU (pdf, English) ¦ Link
  • Cellule de Renseignement Financier (CRF) ¦ Guidelines on the cooperation with the FIU (pdf, French) ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.