CSSF 26/906 · Summary
← Law overview
Partie I - Définitions et champ d’application
Partie I - Définitions et champ d’application
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie III - Entrée en vigueur
Article II.6.1.2
Section 6.1.2 - Les contrôles critiques continus
CSSF Circular 26/906 — Central administration, internal governance and risk management · CSSF 26/906
Section 6.1.2. Les contrôles critiques continus 108. Dans cette catégorie de contrôles tombent notamment :
• le contrôle hiérarchique ;
• la validation (par exemple la double signature, les codes d’accès à des fonctionnalités données) associée au contrôle du respect de la procédure d’autorisation et de délégation de pouvoirs arrêtée par l’organe de gestion ;
• les contrôles réciproques ;
• le relevé régulier de l’existence et de la valeur des éléments du patrimoine et des fonds des utilisateurs de services de paiement, notamment au moyen de la vérification des inventaires ;
• la réconciliation et la confirmation des comptes ;
• le contrôle de l’exactitude et de l’exhaustivité des données communiquées par les personnes en charge des fonctions commerciales et opérationnelles en vue d’un suivi administratif des opérations ;
• la vérification du caractère normal des opérations conclues notamment quant à leur prix, à leur ampleur, aux garanties éventuelles à recevoir ou à fournir, aux bénéfices générés et aux pertes subies, à l’ampleur des frais éventuels.
Le bon fonctionnement de ces contrôles critiques n’est garanti que si le principe de la séparation des tâches est respecté.
Luxgap guidance · DPO & CISO
How to comply
The classic trap Most PSFs and credit institutions document their critical controls in a PDF procedure, then let it drift. The CSSF does not sanction the absence of a procedure, it sanctions the absence of proof of continuous execution : dual signature bypassed under workload pressure, account reconciliation performed but untraced, segregation of duties broken because one person combines initiation and validation of an operation. During an on-site inspection, the CSSF inspector asks for the timestamped evidence of each critical control, not its theoretical existence in a manual.
Segregation of duties: the most sanctioned breaking point The final paragraph of the article is explicit: these controls are worthless without segregation of duties. In practice, the most frequent breaks are:
A single profile holds both initiation AND validation rights for a payment (dual signature bypass). Hierarchical control is nominal: the supervisor signs without effective review or audit trail. Reconciliation and confirmation of accounts are executed by the person who entered the operations. The statement of existence and value of payment service users' funds is not reconciled in due time against actual inventories. The control of the normal character of operations (price, scale, guarantees, fees) is triggered by no automatic threshold and relies on individual vigilance. How Luxgap automates this risk Our Luxgap Control Assurance Engine makes the phantom critical control impossible: it does not merely list your controls, it continuously verifies that they actually execute and that segregation of duties is never broken. The tool connects to your core banking system, your Active Directory or Entra ID, your payment tooling and Sage BOB 50 to cross-check real application rights against the segregation matrix approved by the management body.
Detects in real time any toxic combination of rights (initiation plus validation of a payment on a single AD account) and alerts the management body via Teams before the operation passes. Verifies that each dual signature and each access code to a sensitive function was actually applied, by reconciling application logs against the delegation of powers procedure. Scans reconciliations and account confirmations to confirm they were executed, timestamped and validated by a person distinct from the data entry operator. Calculates a normality score for operations (price, scale, guarantees, fees) and automatically flags deviations requiring review, based on your historical thresholds. Controls the regular statement of existence and value of payment service users' funds against actual inventories. Produces a timestamped, cryptographically sealed PDF report, enforceable before the CSSF during an on-site inspection, demonstrating the continuous execution of each critical control. Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real rights matrices, with a free blind audit within 48h to measure your exposure to segregation of duties breaks before any commitment.
Need help with this article?
Our team (lawyers + cyber engineers) gives you the concrete stuff. Reply within 24 business hours.
📄 Request a template
🤝 Help getting compliant
🔎 Request a review