CSSF 26/906 · Summary
← Law overview
Partie I - Définitions et champ d’application
Partie I - Définitions et champ d’application
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie III - Entrée en vigueur
Luxgap guidance · DPO & CISO
How to comply
The classic trap The CSSF does not sanction the absence of a daily control: it sanctions the absence of evidence that the control actually took place. Point 107 requires operational staff to control their own tasks daily to detect errors and omissions as early as possible. In practice, this first-line control (operational self-control) remains purely declarative: nobody records who checked what, when, and with what result. During an on-site inspection, the CSSF demands the audit trail of these first-line controls, and its absence is a recurring finding of weakness in the internal control framework.
The specific traps of first-line control The daily control exists in the procedure but is never timestamped or signed: impossible to prove afterwards. Outsourced tasks escape control: the institution assumes the provider controls, without a CSSF 22/806 clause requiring control reporting. Detected errors are not logged in a register, so no recurrence analysis and no escalation to second-line control. No clear separation between task execution and its control, which empties the first line of its substance. The materiality threshold triggering escalation is undefined: minor incidents accumulate without traceability. The test expected by the CSSF is simple: for any randomly chosen day, can you demonstrate that the daily control was performed, by whom, and which anomalies were handled? If the answer fits in a non-timestamped Excel file, the framework is deemed insufficient.
How Luxgap automates this risk Our Luxgap Daily Control Attestor turns declarative daily control into an opposable audit trail, without adding workload to your operational staff. The tool integrates with your operational systems (Sage BOB 50, core banking, M365, Odoo, Sopra workflows) and automatically captures the execution and attestation of each first-line control, with timestamping and cryptographic signature linked to the operator Active Directory identity.
Generates each morning the checklist of expected daily controls per process, derived from your internal control procedures, and pushes it to the relevant staff via Teams or email. Captures the timestamped and sealed attestation of each performed control, with the operator identity from Active Directory, and detects missing controls in real time. Automatically logs detected anomalies in a structured register and triggers escalation to second-line control above the defined materiality threshold. Monitors outsourced tasks by verifying receipt of the provider control reporting compliant with CSSF 22/806 requirements, and alerts on missing or late reporting. Produces a timestamped and cryptographically sealed PDF report, opposable during a CSSF on-site inspection, demonstrating the completeness and regularity of daily controls over any chosen period. Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real processes, with a free 48h blank audit to measure your exposure before any engagement.
Need help with this article?
Our team (lawyers + cyber engineers) gives you the concrete stuff. Reply within 24 business hours.
📄 Request a template
🤝 Help getting compliant
🔎 Request a review