CSSF ¦ AMLA Adopts Key Regulatory Technical Standards

CSSF ¦ AMLA Adopts Key Regulatory Technical Standards

The CSSF urges Luxembourg professionals to prepare for AMLA’s first private-sector standards

The Commission de Surveillance du Secteur Financier (CSSF) has asked Luxembourg professionals to start preparing for three draft regulatory technical standards (RTS) adopted by the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). The drafts complement the Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, and cover the definition of business relationships and occasional transactions, customer due diligence (CDD) measures and group-wide arrangements. The CSSF wants firms to finalise their gap analysis and take preparatory steps at Compliance and IT level while the Commission is still reviewing the texts.

Three standards at the core of the single rulebook

All three RTS deal with how obliged entities handle customers. The first determines when a customer contact amounts to a business relationship and when it remains an occasional transaction. That classification decides whether CDD and ongoing monitoring apply from the outset or only once a threshold is reached. The second specifies the content of CDD: the information to be collected and verified on customers, beneficial owners and persons acting on their behalf. The third sets minimum requirements for group-wide policies, procedures and controls.

The AMLR is a directly applicable regulation, and the RTS will take the same form. Detailed CDD expectations that Luxembourg entities have so far derived from national law and CSSF regulation will therefore increasingly be set at EU level.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"The CSSF is telling Luxembourg firms not to wait for the Commission. That is the right call: the three drafts are unlikely to change much in substance, and six months after entry into force is too short to rebuild onboarding data, aggregation rules and group policies from a standing start.

I would treat the gap analysis as a control test as well as a legal mapping. Fund managers in particular should check how the new CDD content reaches their transfer agents and distributors, because that is where the supervisor will look first when it asks how the firm prepared."

Why the supervisor is speaking before the Commission has decided

AMLA has submitted its final reports on the three drafts to the European Commission for adoption and publication. Under Article 49 of Regulation (EU) 2024/1620, which established AMLA, the Commission can still amend the drafts before adopting them, and the CSSF says so openly.

It recommends acting anyway, and the reasoning is sound. The drafts went through consultation, public hearings and close cooperation with national supervisors, and texts at that stage seldom change much in substance before adoption. A firm that waits for the Official Journal will spend the transitional period reacting to a deadline it could have planned for. The communiqué makes clear that the CSSF expects Luxembourg entities to be further along than that.

A six-month runway is short

In each of the three drafts, AMLA proposes a transitional period of six months after the final RTS enter into force following publication in the Official Journal of the EU. That is a tight window for changes to onboarding forms, verification tools, screening logic, transaction monitoring rules and group policies.

Most of the effort sits in implementation. Collecting different data at onboarding means changing forms, client portals, workflow tools and databases. New aggregation rules for linked transactions have to be built into monitoring systems. Revised group arrangements may need board approval and coordination with entities in other jurisdictions. These projects take months, which explains why the CSSF names IT alongside Compliance.

What a meaningful gap analysis looks like

The CSSF asks professionals to base their gap analysis on a review of their internal policies, procedures and controls. A comparison of legal texts alone will miss problems that only show up in the documents and systems staff use every day.

A sensible starting point is classification. Firms should check whether their current distinction between business relationships and occasional transactions, and their method for identifying linked transactions, matches the criteria in the draft RTS. Splitting payments into amounts below the CDD threshold is one of the oldest placement techniques, and harmonised aggregation rules are designed to stop it working.

The CDD review should compare what is actually collected and verified today, product by product and customer type by customer type, with the harmonised requirements. That covers beneficial owners, the purpose and intended nature of the relationship, source of funds and source of wealth in higher-risk cases, remote identification methods, and the screening of politically exposed persons together with their family members and close associates. Every gap needs an owner, a note of its technical dependencies and a deadline.

Entities that belong to a group, or head one, should also test their group-wide framework against the minimum requirements on governance, risk management, internal controls and information sharing. A Luxembourg subsidiary will want to know what its parent will require of it and what information it can expect to receive in return.

A broad range of Luxembourg entities is affected

The communiqué is addressed to credit institutions, investment firms, payment and electronic money institutions, crypto-asset service providers, issuers of tokens, crowdfunding service providers, central securities depositories, specialised and support PFS, mortgage credit intermediaries, investment fund managers, investment funds and vehicles, and securitisation undertakings.

Banks are only one part of that audience. In the investment fund sector, CDD on investors is often carried out by delegates, transfer agents and distributors, so the harmonised requirements will have to find their way into delegation agreements and into the oversight fund managers exercise over those service providers. Crypto-asset service providers and payment institutions rely heavily on remote onboarding and will need to check their identification methods against the new safeguards.

The money laundering risk behind the technical detail

Each standard addresses a known weakness in the defence against money laundering. When providers classify the same customer activity differently, launderers can spread funds across products and institutions to stay below the radar. Weak aggregation of linked transactions lets structuring go unnoticed. Gaps in CDD on beneficial owners and on the relatives and close associates of politically exposed persons leave the proceeds of corruption, fraud and other predicate offenses hidden behind nominees and corporate vehicles, and fragmented group controls let a suspicion raised in one entity stay invisible to the rest of the group.

A gap analysis done well should therefore test whether the firm’s controls would detect these patterns in practice, in addition to recording where the procedures diverge from the new texts.

Preparing for supervisory scrutiny

The AMLR applies from 10 July 2027, and the RTS will be part of the standard against which supervisors assess compliance. Luxembourg entities should expect the CSSF to ask how they prepared, which gaps they found and how they closed them. A documented gap analysis and an implementation plan with named responsibilities, backed by visible progress in Compliance and IT, will be the obvious basis for those conversations.

The CSSF also refers professionals to AMLA’s press release, the final reports on the draft RTS and the explanatory material published with them. The final reports deserve a full read. They explain the policy choices behind individual provisions and show how AMLA responded to consultation feedback, which helps where the wording of a requirement leaves room for interpretation.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • CSSF ¦ AMLA adopts key Regulatory Technical Standards ¦ Link
  • AMLA ¦ Press Release: AMLA finalises key standards for the private sector ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.