The classic trap
The CSSF does not sanction the absence of risk management policies: almost every institution has them. It sanctions the gap between the documented framework and the real economic substance of exposures. Article III.1.1.1 requires a consistent and comprehensive framework at institution level, yet in practice internal control functions work in silos, each business unit manages its risks on its own spreadsheet, and the management body never has a consolidated, defensible view. During an on-site inspection, the CSSF asks for the full risk mapping with limits, alerts and a decision trail: that is where the theoretical framework collapses.
What the CSSF actually checks in your risk management framework
- Is coverage comprehensive? Are all business units AND internal control functions integrated, including at consolidated and sub-consolidated levels?
- Does the framework recognise the economic substance of exposures, or does it stop at legal form (off-balance sheet, indirect exposures, implicit guarantees)?
- Are there operative limits, controls and alerts, or merely declarative thresholds that never trigger?
- Can the management body demonstrate it keeps under control all risks, with a dated audit trail of decisions?
- Are policies and procedures actually applied, or obsolete relative to current activity?
The trap is consistency: a framework fragmented across credit, market, liquidity, operational and compliance risks, without consolidation, does not meet the requirement of an institution-wide framework.
How Luxgap automates this risk
Our Luxgap Risk Consolidation Engine removes the silos that make institutions fail CSSF inspections: it continuously aggregates your real exposures from source systems and produces a single, consolidated, defensible risk map. The tool connects to your core banking (Sopra, Avaloq, Temenos), your limit repositories, M365 and your internal control tools to reconstruct the economic substance of every exposure, without asking your teams to re-enter anything into yet another spreadsheet.
- Automatically aggregates exposures from each business unit and internal control function at institution, consolidated and sub-consolidated levels.
- Detects out-of-framework exposures by cross-checking real economic substance (off-balance sheet, guarantees, indirect exposures) against declared limits.
- Alerts in real time via Teams whenever a limit is breached or a new exposure type appears with no associated policy.
- Verifies that each material risk has an active policy, procedure, limits and alerting mechanism, and flags orphan areas.
- Traces every management body decision with timestamps to evidence effective control of risks.
- Produces a timestamped and sealed risk management framework report, defensible to the CSSF during an on-site inspection.
Available as a complement to a Luxgap CISO or DPO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real data, with a free blank audit within 48h to measure your exposure before any engagement.