CSSF ¦ CSSF Annual Report 2025 Section XXII. Financial Crime

CSSF ¦ CSSF Annual Report 2025 Section XXII. Financial Crime

Luxembourg’s 2025 financial crime lessons: predicate offences, data quality and stronger supervision

Luxembourg’s financial crime supervision entered a more structured phase in 2025 with the creation of a dedicated “Fight against Financial Crime” department within the Commission de Surveillance du Secteur Financier. The new department brings together legal and strategic work relating to money laundering, terrorist financing, proliferation financing, predicate offences and financial restrictive measures.

Its role extends beyond rulemaking. It coordinates supervisory activity across national, European and international levels, contributes to the development of the European anti-money laundering framework and represents Luxembourg in the work of the Financial Action Task Force. Cooperation with the future European supervisor, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, is also becoming a central feature of the supervisory model.

The institutional change reflects a broader reality: financial crime risks cannot be managed through isolated compliance functions. Money laundering, corruption, sanctions evasion, terrorist financing and proliferation financing often overlap, use the same channels and rely on the same weaknesses in customer data, transaction monitoring and governance.

The predicate offence is becoming harder to ignore

A key development in Luxembourg’s legal framework was the amendment of Article 506-1 of the Penal Code through the Law of 12 December 2025. The previous list of primary offences was replaced by a general reference to all crimes and offences.

This change has important consequences for financial institutions. Suspicion of money laundering does not depend on an institution identifying the precise predicate offence. The reporting obligation remains triggered where a professional knows, suspects or has reasonable grounds to suspect that money laundering, an associated predicate offence or terrorist financing has been committed, attempted or is being committed.

The practical message is clear. A bank, investment firm, fund manager, payment institution or crypto-asset service provider is not expected to conduct a criminal investigation before filing a suspicious transaction report. Its responsibility is to recognise credible indicators, document the rationale for its assessment and report promptly to the Financial Intelligence Unit.

This approach is particularly important where the underlying criminal conduct is concealed behind legitimate commercial activity. Proceeds may arise from bribery, fraud, tax offences, cybercrime, trafficking, embezzlement or other criminal conduct. Once those proceeds enter the financial system, the focus must shift from proving the underlying offence to identifying whether the activity, funds or transaction pattern gives rise to a reasonable suspicion of laundering.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Luxembourg’s 2025 supervisory priorities show that effective anti-money laundering controls depend on more than policies and checklists. Institutions must understand predicate offences such as corruption and fraud, maintain accurate customer data, monitor transactions against the customer’s actual profile and report suspicion promptly without needing to identify the precise underlying crime.

The supervisory focus also extends to sanctions compliance, crypto-assets, terrorist financing and the quality of outsourced controls. Strong frameworks require timely alert handling, meaningful risk assessments, clear accountability and evidence that deficiencies are remediated rather than merely recorded."

Corruption identified as a priority laundering risk

Bribery was identified as a predicate money laundering offence requiring particular attention. The risk assessment for Luxembourg’s financial sector continues to show significant exposure to money laundering, while corruption presents specific challenges for customer due diligence and transaction monitoring.

Corruption proceeds can be difficult to detect because they are frequently disguised as consulting fees, commissions, procurement payments, investment returns, loans, gifts or transactions involving related parties. The funds may move through several jurisdictions and legal entities before reaching a bank account, investment structure or asset acquisition.

The involvement of politically exposed persons creates an additional layer of risk. Institutions must not treat politically exposed person status as proof of wrongdoing, but it should lead to appropriate enhanced measures. These may include establishing the source of wealth and source of funds, obtaining senior management approval where required, applying enhanced monitoring and reassessing the relationship when new information appears.

A strong corruption risk framework should also consider the customer’s business sector, public procurement exposure, links to state-owned entities, jurisdictions involved, use of intermediaries and unusual changes in wealth. Transaction monitoring should be capable of identifying payments that are inconsistent with the stated purpose of the relationship, particularly where the customer operates in sectors vulnerable to bribery or public-sector influence.

The growing focus on corruption is consistent with developments at European level. The European Union’s anti-corruption framework is moving towards more harmonised criminalisation and enforcement of active and passive bribery in both public and private sectors. For financial institutions, this reinforces the need to connect anti-bribery controls with AML processes rather than treating them as separate compliance topics.

Supervisory findings show that execution remains the main weakness

The supervisory programme combined questionnaires, bilateral meetings, automated reviews, supervisory colleges and on-site inspections. More than 6,000 off-site supervisory measures were carried out, 504 observation letters were issued and nine administrative sanctions followed failures to file AML/CFT reports. In addition, 37 AML/CFT on-site inspections covered banks, specialised professionals of the financial sector, investment firms, management companies, payment institutions, electronic money institutions and crypto-asset service providers.

The findings point less to the absence of policies than to weaknesses in their practical operation. Recurring issues included incomplete consideration of high-risk countries, delays in periodic customer reviews, weaknesses in transaction monitoring and inadequate follow-up of internal control findings.

These are not merely procedural shortcomings. A delayed customer review may leave an institution relying on outdated ownership, identification or business information. A weak transaction monitoring scenario may fail to detect the movement of criminal proceeds. An ineffective compliance review may allow the same control deficiency to persist across several reporting cycles.

The supervisory emphasis therefore remains firmly on evidence. Institutions must be able to demonstrate that their controls operate in practice, that alerts are handled within appropriate timeframes and that remediation is tracked until weaknesses have been properly addressed.

Customer data is the foundation of effective detection

On-site inspections highlighted the importance of customer database quality. Screening and risk-scoring systems cannot compensate for incomplete, inaccurate or outdated information.

This issue is especially relevant where customers provide data themselves or where information is transferred between group entities, distributors, delegates or outsourced service providers. Missing names, incorrect dates of birth, incomplete ownership information or absent counterparties can prevent the identification of sanctions exposure, politically exposed persons, adverse information and links to criminal activity.

The same problem affects transaction monitoring. A system cannot reliably identify activity inconsistent with a customer profile if that profile does not accurately describe the customer’s business, expected volumes, countries, counterparties and source of funds.

Data governance should therefore be treated as a financial crime control, not as an administrative matter. Institutions should define ownership of key data fields, conduct regular quality testing and establish escalation procedures for material inaccuracies. Changes in beneficial ownership, management, business activity or geographic exposure should be reflected promptly in the customer risk assessment.

Sanctions alerts require immediate operational capacity

The treatment of name-screening alerts was another significant supervisory concern. Alerts relating to persons, entities or groups subject to financial restrictive measures must be handled without delay. Where an institution cannot review an alert quickly, it must take interim measures to ensure that a potential restriction can be applied.

This is distinct from the handling of ordinary false positives. A backlog involving sanctions alerts can create direct legal and operational exposure, particularly where funds are made available to a designated person or an institution continues to process a prohibited transaction.

The effectiveness of sanctions screening depends on more than the quality of the screening tool. Institutions need accurate customer and counterparty data, complete coverage of distributors and discretionary portfolio management customers, documented false-positive decisions and a clear process for freezing or stopping activity where necessary.

The legal significance of this area is increasing. Circumvention and attempted circumvention of financial sanctions are becoming criminal risks under European law. Sanctions compliance can no longer be viewed only as a technical screening exercise. It requires an understanding of ownership and control, indirect transactions, trade routes, intermediaries, payment systems and the potential use of crypto-assets to bypass restrictions.

Suspicious transaction reporting does not end with the first report

Supervisory observations also addressed delays in reporting suspicious activity. Under Luxembourg’s AML framework, professionals must inform the Financial Intelligence Unit promptly when they know, suspect or have reasonable grounds to suspect money laundering, an associated predicate offence or terrorist financing.

A refusal to execute a transaction does not remove the reporting obligation. Nor does filing an initial report necessarily conclude the institution’s responsibilities. Once a relationship or transaction has generated suspicion, enhanced monitoring may be necessary to identify subsequent activity. Where further suspicious transactions occur, a complementary report may be required.

This principle is particularly important in predicate offence cases. A customer may initially present a transaction linked to a suspected fraud, bribery payment or tax offence. Subsequent payments, transfers to related entities or rapid movement of funds may provide additional information about the laundering process or the wider network involved.

Institutions should therefore maintain a clear connection between suspicious transaction reporting, ongoing monitoring, account restrictions and exit decisions. The relevant records should show what was identified, when it was escalated, why a report was filed and how the relationship was managed afterwards.

The risk-based approach is not a checklist

The supervisory message regarding customer due diligence was direct: AML analysis cannot be reduced to collecting documents and updating them at predetermined intervals.

Periodic reviews should test whether the account’s actual operation remains consistent with the customer profile and with the stated purpose and nature of the business relationship. The institution should consider transaction behaviour, counterparties, geographic exposure, changes in ownership, new products, unusual payment patterns and information obtained from internal or external sources.

This is particularly important for customers whose activity changes over time. A company may begin with a modest domestic business and later receive large international payments, deal in high-risk goods or transact with entities that were not part of the original business model. A checklist may confirm that identification documents are present, while an analytical review may reveal that the relationship no longer makes economic or commercial sense.

The risk-based approach also requires proportionality. High-risk situations should receive enhanced attention, but lower-risk relationships should not automatically be subjected to unnecessary restrictions. Updated guidance from the FATF places emphasis on enhanced measures where required, while recognising that simplified measures may be appropriate where risks are demonstrably lower. Poorly calibrated controls can create both compliance gaps and unjustified de-risking.

Blocked accounts need a clear risk distinction

A thematic review of blocked accounts in the collective management sector found that only a limited proportion related to concrete AML/CFT risks. Many blockings resulted from periodic reviews and the collection of expired identification documents.

This distinction matters. An account blocked because a periodic review is incomplete does not necessarily present the same risk as an account blocked because of suspected money laundering, sanctions exposure or terrorist financing. Combining both categories can distort risk reporting, obscure the institution’s actual exposure and make management information less useful.

A sound framework should distinguish the reason for the restriction, define the conditions for unblocking and ensure that genuine financial crime concerns are escalated separately. Good practices included dedicated testing of blocked accounts, regular reporting to boards and specific oversight of delegates responsible for investor registers.

An expired identity document should not automatically result in blocking solely because it has expired. The appropriate response depends on the customer’s risk, the document concerned and any doubt about the continued accuracy of the identification data. Blocking may be necessary where specific AML/CFT concerns exist, but the response should be based on risk rather than an automatic administrative rule.

Crypto-assets require specialised control frameworks

Payment institutions, electronic money institutions and crypto-asset service providers faced heightened supervisory attention in 2025. The focus included the Travel Rule, self-hosted addresses, transaction monitoring, blockchain analysis and the adequacy of human and technical resources.

Crypto-asset businesses need staff who understand both the products and the associated financial crime risks. Conventional transaction monitoring approaches may not be sufficient where funds move across multiple wallets, decentralised services, mixers, bridges or jurisdictions with differing levels of control. Institutions should be able to explain how blockchain analytics are used, how risk indicators are weighted and how alerts are investigated.

Thematic reviews also examined counter-terrorist financing controls. Relevant capabilities may include scenarios for identifying small-value transfers, activity involving high-risk locations, payment messages containing relevant terms and patterns associated with fundraising or facilitation.

Technology can strengthen controls, including tools that detect forged documents, compare faces with identity documents, analyse location data or identify unusual transactions within peer groups. Yet complex or AI-supported systems must remain explainable and subject to formal testing. Institutions retain responsibility for their controls even where processes are outsourced or supported by advanced technology.

European supervision will increase consistency and scrutiny

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism began its operational activities in 2025. Its responsibilities include developing technical standards, supporting common risk methodologies, coordinating national supervision and promoting cooperation among financial intelligence units and supervisory authorities.

Direct supervision of selected complex and higher-risk entities is expected to begin from mid-2028, with crypto-asset service providers identified as an early strategic priority. The transfer of anti-money laundering powers from the European Banking Authority to the new authority from January 2026 further consolidates the European supervisory structure.

For supervised firms, this means that local compliance frameworks will increasingly be assessed against common European expectations. Differences in national practice are likely to narrow, while documentation, data quality, governance and evidence of effective control will receive greater attention.

The core lesson for financial institutions

The supervisory priorities for Luxembourg’s financial sector point to a common conclusion: effective financial crime compliance depends on connecting legal obligations with operational judgement.

Institutions must understand the risks created by predicate offences, particularly corruption and fraud. They must maintain reliable customer and ownership data, monitor transactions in a way that reflects the customer’s actual activity and report suspicion promptly without waiting to identify the exact underlying crime. They must also distinguish AML/CFT restrictions from routine administrative blockings, manage sanctions alerts without delay and maintain oversight of outsourced or group-level controls.

The most resilient frameworks are not those with the longest procedures. They are those that produce reliable information, generate meaningful alerts, support timely decisions and create a defensible audit trail. In a supervisory environment shaped by AMLA, expanding sanctions risks, crypto-assets and increasingly sophisticated predicate offences, that operational standard will determine whether an institution’s controls are merely documented or genuinely effective.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.