The classic trap
Section 6.1.1 requires that first-level control be performed daily by the executing staff themselves, in real time. What the CSSF sanctions in practice is not the absence of an internal control policy, but the absence of evidence that these daily controls actually took place: an untraced cash reconciliation, an unmonitored open item, a trading position never verified by the trader. During an on-site inspection, the CSSF asks for the audit trail of first-level control, and a purely declarative control, or one performed retroactively in bulk, is reclassified as a governance failure under the circular.
What the CSSF actually expects from first-level control
- A control performed on the same day as the operation, not at week-end or during month-end closing.
- A timestamped audit trail: who controlled what, when, and with what outcome (compliant / discrepancy detected).
- Active management of open items and discrepancies: every anomaly must be opened, assigned, then closed with supporting evidence.
- A clear separation between the executor controlling their own work (level 1) and the compliance or risk function supervising (level 2).
- Formalised escalation of recurring errors and omissions to authorised management.
- Real coverage of all sensitive positions: cash, trading positions, reconciliations, accounting and securities open items.
The main trap: many institutions document the procedure but keep no opposable evidence of its daily execution. Before the CSSF, a procedure without an audit trail counts as no control at all.
How Luxgap automates this risk
Our Luxgap Daily Control Trail turns first-level control, often informal and unverifiable, into a timestamped audit trail opposable to the CSSF. The tool connects to your core banking system, your trading systems (Bloomberg, front-office orders), Sage BOB 50 and your M365 document management to detect in real time which operations have been executed, then automatically chases the executor until the associated daily control is attested, without the compliance function having to run after the evidence.
- Automatically detects each routine transaction requiring first-level control and generates the daily verification task assigned to the right executor.
- Alerts the executor and their manager via Teams as soon as a cash reconciliation, an open-item follow-up or a position check is not closed by end of business day.
- Traces each control with timestamp, controller identity and outcome, forming the audit trail required by Section 6.1.1.
- Tracks the full lifecycle of each open item and discrepancy, from opening to justified closure, and automatically escalates untreated anomalies to authorised management.
- Calculates a daily coverage rate of first-level control and flags sensitive positions left unverified.
- Produces a timestamped and sealed PDF report, opposable during a CSSF inspection, demonstrating the effective execution of daily controls by executing staff.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free blind audit within 48h to measure your exposure before any commitment.