CSSF 26/906 · Summary
← Law overview
Partie I - Définitions et champ d’application
Partie I - Définitions et champ d’application
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie III - Entrée en vigueur
Article II.6.2.1
Section 6.2.1 - Responsabilités génériques des fonctions de
CSSF Circular 26/906 — Central administration, internal governance and risk management · CSSF 26/906
Section 6.2.1. Responsabilités génériques des fonctions de contrôle interne 114. Les fonctions de contrôle interne ont pour objectif principal de vérifier le respect de l’ensemble des politiques et des procédures internes qui tombent dans leur champ d’attribution, d’en évaluer régulièrement l’adéquation par rapport à la structure organisationnelle et opérationnelle, aux stratégies, aux activités et aux risques de l’établissement ainsi que par rapport aux exigences légales et réglementaires applicables et d’en rendre compte directement à l’organe de gestion ainsi qu’à l’organe de surveillance et, le cas échéant, aux comités spécialisés. Elles fournissent à l’organe de gestion ainsi qu’à l’organe de surveillance et, le cas échéant, aux comités spécialisés les avis et conseils qu’elles jugent utiles ou qui leur sont demandés par ces organes ou comités. Nonobstant les responsabilités spécifiques en la matière attribuées à la fonction compliance, toutes les fonctions de contrôle interne contribuent à la lutte efficace contre le blanchiment et le financement du terrorisme.
115. Lorsqu’ils estiment que la gestion efficace, saine ou prudente des activités est compromise, les responsables des fonctions de contrôle interne en informent promptement et de leur propre initiative l’organe de gestion et l’organe de surveillance et les comités spécialisés, le cas échéant.
Luxgap guidance · DPO & CISO
How to comply
The classic trap This article is deceptively generic, and that is exactly where the CSSF sanctions. The three internal control functions (compliance, risk management, internal audit) must not only exist but document their continuous verification activity, their adequacy reassessed on a regular basis, and above all their direct reporting to the management body and the supervisory body. In practice, the CSSF finds that point 115 (the duty to raise a prompt and spontaneous alert) remains theoretical: when a function believes sound management is compromised, the escalation is neither traced, timestamped, nor provable. The absence of an audit trail on these escalations turns paper governance into a finding during on-site inspections.
What the CSSF actually checks on control functions The dated evidence that each function periodically reassesses the adequacy of its framework against the strategies, activities and risks of the institution. The direct reporting to both the management body AND the supervisory body, without any intermediate hierarchical filter. The documented contribution of all functions (not only compliance) to the fight against money laundering and terrorist financing. The traceability of the spontaneous alerts under point 115: who alerted, when, on what, and how the body responded. The consistency between the advice given to specialised committees and the decisions actually taken. The effective independence of the functions and their unhindered access to information. How Luxgap automates this risk Our Luxgap Control Function Cockpit makes it impossible to miss an escalation and turns every alert from your control functions into timestamped evidence enforceable before the CSSF. The tool connects to your M365, your GRC platform, your messaging and your committees (Outlook agendas, SharePoint minutes) to automatically reconstruct the full audit trail of compliance, risk and internal audit reporting to the management and supervisory bodies, without asking your officers to keep a manual register.
Automatically detects each formal escalation to the management and supervisory bodies from your M365 and SharePoint flows and timestamps it in a tamper-proof way. Computes an adequacy score per function, reassessed whenever a change in strategy, activity or risk profile is recorded in your GRC tool. Alerts via Teams as soon as a point 115 alert (compromised management) is raised but remains without a documented response from the body beyond the deadline you set. Verifies that all three functions effectively contribute to the AML/CFT framework by cross-checking their deliverables against the applicable regulatory obligations. Generates a timestamped and sealed PDF report, enforceable during a CSSF inspection, demonstrating the reality and independence of internal control function reporting. Available as a complement to a Luxgap CISO or DPO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real committees, with a free blind audit within 48h to measure your exposure before any commitment.
Need help with this article?
Our team (lawyers + cyber engineers) gives you the concrete stuff. Reply within 24 business hours.
📄 Request a template
🤝 Help getting compliant
🔎 Request a review