CSSF Circular 12/552 on central administration, internal governance and risk management.
The CSSF framework for internal governance and control of banks and investment firms.
Circular contents
All 58 sections, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- I.1. Chapitre 1 - Définitions et abréviations
- I.2. Chapitre 2 - Champ d’application et proportionnalité
- II.1. Chapitre 1 - L’administration centrale
- II.2. Chapitre 2 - Le dispositif de gouvernance interne
- II.3. Chapitre 3 - Propriétés génériques d’un dispositif « solide » en
- II.4.1.1. Section 4.1.1 - Responsabilités de l’organe de surveillance
- II.4.1.2. Section 4.1.2 - Composition et qualification de l’organe de
- II.4.1.3. Section 4.1.3 - Organisation et fonctionnement de l’organe de
- II.4.1.4. Section 4.1.4 - Comités spécialisés
- II.4.2.1. Section 4.2.1 - Responsabilités de la direction autorisée
- II.4.2.2. Section 4.2.2 - Qualification de la direction autorisée
- II.5.1. Sous-chapitre 5.1 - L’organigramme et les ressources humaines
- II.5.2. Sous-chapitre 5.2 - Les procédures et la documentation interne
- II.5.3.1. Section 5.3.1 - L'infrastructure administrative des fonctions
- II.5.3.2. Section 5.3.2 - La fonction financière et comptable
- II.5.3.3. Section 5.3.3 - La fonction informatique
- II.5.3.4. Section 5.3.4 - Le dispositif de communication et d’alerte
- II.5.3.5. Section 5.3.5 - Le dispositif de gestion de crises
- II.6. Chapitre 6 - Le contrôle interne
- II.6.1.1. Section 6.1.1 - Contrôles quotidiens réalisés par le personnel
- II.6.1.2. Section 6.1.2 - Contrôles critiques continus
- II.6.1.3. Section 6.1.3 - Contrôles réalisés par les membres de la
- II.6.2. Sous-chapitre 6.2 - Les fonctions de contrôle interne
- II.6.2.1. Section 6.2.1 - Responsabilités génériques des fonctions de
- II.6.2.2. Section 6.2.2 - Caractéristiques des fonctions de contrôle
- II.6.2.3. Section 6.2.3 - Exécution des travaux des fonctions de contrôle
- II.6.2.4. Section 6.2.4 - Organisation des fonctions de contrôle interne
- II.6.2.5. Section 6.2.5 - La fonction de gestion des risques
- II.6.2.6. Section 6.2.6 - La fonction compliance
- II.6.2.7. Section 6.2.7 - La fonction d’audit interne
- II.7.1. Sous-chapitre 7.1 - Structure organisationnelle et entités juridiques
- II.7.1.1. Section 7.1.1 - Structures complexes et activités inhabituelles
- II.7.2. Sous-chapitre 7.2 - Gestion des conflits d’intérêts
- II.7.2.1. Section 7.2.1 - Exigences spécifiques relatives aux conflits
- II.7.2.2. Section 7.2.2 - Documentation des prêts accordés aux
- II.7.3. Sous-chapitre 7.3 - Procédure d’approbation des nouveaux produits
- II.7.4. Sous-chapitre 7.4 - Externalisation (« Outsourcing »)
- II.8. Chapitre 8 - Reporting légal
- III.1.1.1. Section 1.1.1 - Généralités
- III.1.1.2. Section 1.1.2 - Politiques spécifiques (de risque, de fonds
- III.1.1.3. Section 1.1.3 - Détection, gestion, mesure et déclaration des
- III.2. Chapitre 2 - Risques de concentration
- III.3.1. Sous-chapitre 3.1 - Principes généraux
- III.3.2. Sous-chapitre 3.2 - Expositions aux particuliers garanties par une
- III.3.3. Sous-chapitre 3.3 - Expositions aux promotions immobilières
- III.3.4. Sous-chapitre 3.4 - Expositions présentant un risque particulièrement
- III.3.5. Sous-chapitre 3.5 - Expositions non performantes et expositions
- III.4. Chapitre 4 - Tarification du risque (« Risk Transfer Pricing »)
- III.5. Chapitre 5 - Gestion patrimoniale privée (« banque privée »)
- III.6.1. Sous-chapitre 6.1 - Mise en œuvre de principes de contrôle interne
- III.6.2. Sous-chapitre 6.2 - Application de limites quantitatives
- III.7. Chapitre 7 - Risque de charge pesant sur les actifs (« asset
- III.8.1. Sous-chapitre 8.1 - Risque de taux d’intérêt inhérent aux activités autres
- III.8.2. Sous-chapitre 8.2 - Corrections de la duration modifiée des titres de
- III.9. Chapitre 9 - Risques liés à la conservation d’actifs financiers par
Who is concerned?
This circular is broken down into 58 sections analysed one by one, each with the official text and Luxgap practical guidance for compliance in Luxembourg.Key obligations
The CSSF framework for internal governance and control of banks and investment firms.
Luxgap supports CSSF-supervised entities (banks, PFS, payment and e-money institutions, management companies, funds) in complying with this circular: gap analysis, policy and register updates, CSSF inspection readiness, articulation with the DORA Regulation and the NIS 2 framework where relevant.
Deadlines
See the official CSSF text for precise application dates. Most recent ICT circulars articulate with the DORA Regulation, applicable since 17 January 2025.
Sanctions for non-compliance
Non-compliance exposes entities to CSSF administrative sanctions: injunctions, pecuniary sanctions, restrictions or suspension of authorisation.
How Luxgap helps
The CSSF framework for internal governance and control of banks and investment firms.
Luxgap supports CSSF-supervised entities (banks, PFS, payment and e-money institutions, management companies, funds) in complying with this circular: gap analysis, policy and register updates, CSSF inspection readiness, articulation with the DORA Regulation and the NIS 2 framework where relevant.
Let's discuss your situation.
This topic is handled case by case. Get in touch to discuss it: reply within one business day, no commitment.
Contact us →