The classic trap
Chapter 5 of CSSF 20/758 requires a documented and coherent administrative, accounting and IT organisation. The trap: institutions describe their organisation chart and procedures on paper, but the CSSF sanctions the gap between the declarative and operational reality. During an on-site inspection or an ICAAP/ILAAP review, the authority checks that the financial, accounting and IT functions have effective human resources, up-to-date documentation and a genuinely operable crisis management framework. An outdated procedure, an organisation chart misaligned with real system access, or an under-resourced IT function is enough to establish a governance breach.
The concrete control points of chapter 5
- Up-to-date organisation chart reflecting real responsibilities and segregation of duties (sub-chapter 5.1).
- Internal procedures dated, versioned and regularly reviewed, not ghost documents (sub-chapter 5.2).
- Financial and accounting function with traceable reconciliation controls (section 5.3.2).
- IT function aligned with the circular and related ICT requirements, with access mapping (section 5.3.3).
- Internal and external communication and alert framework tested, not merely drafted (section 5.3.4).
- Crisis management framework with scenarios, roles and documented exercises (section 5.3.5).
The tipping point before the CSSF is always the same: can you demonstrate, with time-stamped evidence, that your described organisation matches your actual organisation on the date of the inspection?
How Luxgap automates this risk
Our Luxgap Governance Sync makes the gap between your declared organisation and your real organisation impossible. The tool fetches the truth from your systems itself: it cross-references Active Directory, Microsoft 365, your HR tool (Workday LU, Sopra Steria HR Suite), your accounting system (Sage BOB 50, Cegid Quadra) and your document manager to rebuild a living organisation chart and confront each procedure with its actual usage, without asking the compliance officer to fill in a single spreadsheet.
- Automatically rebuilds the real organisation chart from Active Directory roles and HR data, and alerts whenever a system access matches no declared function.
- Detects internal procedures not reviewed past their update deadline and computes a documentation freshness score per function.
- Maps segregation of duties on the financial and accounting functions by analysing Sage BOB 50 rights and validation workflows.
- Verifies that the crisis management framework and alert chain hold valid contacts and dated exercises, and flags scenarios never tested.
- Produces a time-stamped PDF report enforceable before the CSSF during an on-site inspection, demonstrating consistency between declared and operational organisation.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blind audit within 48h to measure your exposure before any commitment.