The classic trap
Recital 14 addresses pooled and joint TLPTs, where several financial entities share critical ICT systems and mutualise a single test. The trap that the CSSF and the BCL sanction in practice is not the test itself, but the ambiguity over role allocation: the designated entity assumes it has absorbed every obligation, while participating entities loosen their own governance. Yet this recital is explicit, the obligations of each participating entity remain unaffected during the pooled test. Every financial entity stays individually responsible for its remediation, its ICT risk management (CSSF circular 20/750) and the oversight of its own ICT providers (circulars 22/806 and 25/882).
How this recital translates into the articles
This recital clarifies the RTS articles on the role of the designated entity and on the interface with the lead TLPT authority. In practice, within a TIBER-LU framework (Implementation Document revised on 20 June 2025), you must map who carries what before the test even starts.
- The designated financial entity provides all necessary documentation to the lead TLPT authority and monitors the test process.
- The designated entity handles the common aspects of the risk management assessment, but not the individual remediation of each participant.
- Each participating entity keeps its internal white team, its scoping of its own critical functions and its live-production security responsibility (DORA art. 26-27).
- ICT providers within the test scope must be covered by the outsourcing RTS 2025/532 clauses and by circulars 22/806 and 25/882.
- Remediation from the test feeds the ICT risk management framework of each entity (circular 20/750), not only that of the designated entity.
How Luxgap automates this risk
Our Luxgap Pooled TLPT Orchestrator makes the accountability gap in a pooled test impossible: it materialises, for each participating entity and for the designated entity, an enforceable RACI matrix proving to the CSSF and the BCL that DORA article 26 obligations are covered with no grey zone. The tool connects to your governance repositories (M365, Azure Sentinel, Odoo contracts, ICT provider registers) to automatically reconstruct the real scope of the critical functions shared across entities.
- Automatically maps the critical functions common to several entities and identifies the mutualised ICT systems eligible for pooled testing.
- Generates the RACI matrix aligned with recital 14, separating the designated entity tasks (documentation, monitoring, common risk management aspects) from the residual obligations of each participant.
- Tracks ICT providers within scope and verifies their contractual coverage under RTS 2025/532 and circulars 22/806 and 25/882.
- Alerts in real time via Teams whenever an individual remediation action is attached to no responsible entity, before the CSSF spots it.
- Injects each remediation plan into the ICT risk management framework of the relevant entity, tracing the link with circular 20/750.
- Produces a timestamped and sealed PDF file, enforceable before the lead TLPT authority, demonstrating the clear allocation of roles ahead of test launch.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blank audit within 48h to measure your exposure before any engagement.