The classic trap
The CSSF does not sanction the absence of critical controls on paper, but their operational non-existence. Institutions list dual signature, reciprocal controls and account reconciliation in their procedures, then, under business pressure, let the same person initiate, validate and book an operation. The weakness surfaces at the first on-site inspection: segregation of duties is not demonstrable in the system, only asserted in a binder. The CSSF then reclassifies the internal control framework as deficient under the circular, with a remediation order and enhanced monitoring.
Where segregation of duties breaks in practice
- One officer holds both the right to initiate a transfer and the right to validate it in the payment tool (undetected accumulation of entitlements).
- Dual signature is configured but both signatories belong to the same team and cover for each other (fictitious reciprocal control).
- Account reconciliation is performed by the person who booked the entries, so without independent oversight.
- Internal limits set by authorised management are not hard-coded in the system and rely on human vigilance.
- The control of the normal nature of operations (price, size, brokerage fees) is not traced: no timestamped proof it took place.
- Access codes to sensitive functions are not reviewed after an internal move, leaving orphan rights.
The text is explicit: the proper functioning of continuous critical controls is only guaranteed if segregation of duties is respected. The CSSF expects systemic proof of this segregation, not a declarative one.
How Luxgap automates this risk
Our Luxgap Duty Segregation Sentinel makes silent accumulation of incompatible entitlements impossible by continuously mapping who can do what across your real systems. The tool pulls entitlement matrices from Active Directory, Sage BOB 50, Microsoft 365 and your payment platforms, then cross-references each access combination against a conflict matrix (initiate / validate / book / reconcile) aligned with the requirements of section 6.1.2, without asking the compliance team to fill in a single spreadsheet.
- Detects in real time (5-minute cron) any user accumulating two incompatible roles as soon as an entitlement is added in Active Directory or the payment tool.
- Checks that the two signatories of a dual signature do not belong to the same unit and flags fictitious reciprocal controls.
- Maps sensitive functions protected by access codes and flags orphan rights after an internal move.
- Hard-codes internal limits set by authorised management and alerts instantly on Teams whenever an operation exceeds the threshold.
- Traces every control of the normal nature of operations (price, size, brokerage fees) with timestamps, to prove it actually took place.
- Produces a timestamped, cryptographically sealed PDF report, enforceable before the CSSF, demonstrating effective segregation of duties article by article.
Available alongside a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real entitlement matrix, with a free blind audit within 48h to measure your duty conflicts before any commitment.