- Conference of January 22nd, 2024
The 2024 AML/CTF Conference for Specialised PFS offered deep insights into the challenges and best practices in anti-money laundering and counter-terrorist financing.
The following areas have been identified as presenting the most common findings from both onsite inspections and offsite investigations:
- Name screening process;
- Transaction monitoring;
- Client risk assessment;
- RC report;
- Cooperation with the authorities.
Name Screening Process
The name screening process emerged as a pivotal area with common challenges such as:
- All parties connected to a client's relationship have not been recorded.;
- Some recorded parties have not been linked to the respective clients.;
- Delays in updating the database with new records;
- Delays in addressing alerts and unresolved hits;
- The four-eyes principle has not been applied to the analysis of alerts;
- Insufficient oversight when name screening duties are contracted out;
- The analyses have not been sufficiently formalised.;
- Lack of checks on the timely incorporation of Terrorist Financing Sanctions (TFS) lists in the screening tool.
The CSSF has reminded us of the following best practices:
- Maintain a comprehensive database as mandated by Article 39(2) of CSSF Regulation N° 12-02;
- Conduct screenings daily or coinciding with the release of TFS lists.
Article 33(1) of CSSF Regulation N° 12-02 states that the screening must be carried out «without delay».; - Address alerts immediately as stipulated in Article 33 of the CSSF Regulation N° 12-02;
- Implement the four-eyes principle for data entry into the database and the processing of alerts (both false and genuine);
- Formally document the analysis process systematically as per Article 39(3) of CSSF Regulation N° 12-02;
- Routinely verify the screening tool's functionality to ensure its proper operation;
- Ensure that the management of false alerts is overseen when name screening responsibilities are outsourced.
Transaction Monitoring
The following issues have been identified by the CSSF:
- Absence of transaction monitoring procedures.;
- Unclear understanding of client transaction purposes and underlying reasons;
- Insufficient focus on scrutinising complex and exceptionally large transactions;
- Failure of staff to carry out coherence checks or to identify warning signs;
- Non-application of the four-eyes principle in monitoring and analysis;
- Lack or inadequacy of formalisation and documentation for transaction analysis.
The CSSF has reminded us of the following best practices:
- Carry out transaction monitoring as described in Article 3(2)(d) of the AML/CFT Law;
- Enhance critical thinking skills and carry out coherence checks to ensure transaction integrity;
- Offer tailored AML/CFT training for staff and management, focusing on specific activities, typologies, awareness of red flags, and case studies, in accordance with Article 4(2) of the AML/CFT Law and Article 46 of CSSF Regulation N° 12-02;
- Implement the four-eyes principle in the oversight of transaction monitoring to bolster scrutiny and accuracy;
- Formally document the transaction analysis process systematically, as required by Article 39(3) of CSSF Regulation N° 12-02.
Client Risk Assessment
The following issues have been identified by the CSSF:
- The coverage of risk factors as specified in Article 3(2a) of the AML/CFT Law is incomplete, failing to fully encompass customer types, geographic locations, products, services, transaction types, and delivery channels.;
- Misclassification of client risks results in inadequate due diligence actions and incorrect intervals for reviewing client files.;
- There is a lack or deficiency in the formalisation of the risk analysis process.
The CSSF has reminded us of the following best practices:
- Ensure comprehensive consideration of all risk factors outlined in the AML/CFT Law;
- Accurately assign risk ratings to clients to reflect their true risk level;
- Adjust due diligence efforts and the frequency of client file reviews to match the assessed risk rating of each client;
- Prioritise and allocate more resources towards managing high-risk clients;
- Formalise and document the risk analysis process to enhance clarity, consistency, and compliance.
RC Report
The following issues have been identified by the CSSF:
- The RC report contains insufficiently detailed information;
- The RC report does not contain all the requested points.
To address these deficiencies the CSSF reminds that, when formalising its summary report, the RC shall consider all the elements mentioned in the:
- Article 42(5) of CSSF Regulation n°12-02 as amended;
- Point 50 of the EBA guidelines.
Cooperation Requirements
The following issues have been identified by the FATF:
There are a low number of reports filed.;
A significant number of reports are prompted by negative media coverage, without adequate analysis to determine if there are grounds for suspicion before the report is filed.
To address these issues, the CSS
You are free to submit a report to the FIU whenever necessary.;
However, ensure that your reports are substantive and provide value to the FIU, rather than submitting them without substantial reason.
Useful links
Discover our AML/CTF services
Discover our other publications:

Roadmap: building your GRC framework step by step
An effective GRC framework is built progressively, from the diagnosis of the existing state to consolidation, by adapting each step to the maturity, size and priorities of the organisation.

GRC reporting: giving the board an overview
A useful GRC reporting consolidates the work of control functions into a readable view allowing the board to identify developments, areas of concern and decisions to be made.

Data, evidence and traceability: the foundation of a credible system
A credible monitoring system relies on reliable data, structured evidence and an audit trail making it possible to reconstruct decisions and actions throughout the activity.