- Central administration
- Internal governance
- Risk Management
- Abrogates and replaces CSSF Circular 12/552 as amended concerning investment firms.
- Applicable from 1 January 2021.
Key elements
- Circular CSSF 20/758 applies to Luxembourg investment firms, including their branches, as well as to Luxembourg branches of third-country investment firms.;
- Financial companies and mixed financial holding companies have entered the scope of this CSSF Circular.;
- Circular CSSF 12/552 remains fully applicable to credit institutions and partly to professionals carrying out lending operations.
A. Governance
Principle of proportionality
- Further details concerning the principle of proportionality are provided depending on whether or not an establishment is classified as significant. The CSSF circular refers to systemically important investment firms (Article 59-3 of the amended law of 5 April 1993 on the financial sector).
- The notion of "independence of mind" has been introduced within this CSSF circular.
Independent members on the Board of Directors
- In principle, every investment firm must appoint at least one member to its board of directors considered an "independent member".
- Undertakings, which are of significant importance or whose shares are admitted to trading on a regulated market, must ensure that their board of directors has a sufficient number of independent members, taking into account their organisation and the nature, scale, and complexity of their activities.
Specialised committees
- Undertakings, which are of significant importance or whose shares are admitted to trading on a regulated market, must ensure that their board of directors has a sufficient number of independent members, taking into account their organisation and the nature, scale, and complexity of their activities.
- Organisations that are not of significant size may establish dedicated committees that combine different areas of responsibility.
B. Responsibilities
The Chief Financial Officer (CFO)
- The Chief Financial Officer ("CFO") is currently considered a key function within the organisation. These activities have a significant influence on the conduct or control of the establishment's activities.
- In establishments of significant importance, the CFO is selected, appointed and dismissed according to a written internal procedure, with prior approval from the board of directors.
The Chief Risk Officer ("CRO")
- The Chief Risk Officer ("CRO") must be able to challenge executive management decisions. These challenges and the reasons given must be documented by the institution.
- When the establishment grants the CRO a veto over authorised management decisions, the scope of this right must be clearly and in writing agreed, including the escalation process to the board of directors.
- Decisions that have received a reasoned negative opinion from the CRO should be subject to an enhanced decision-making process.
The Chief Compliance Officer
- The head of the compliance function (Chief Compliance Officer, "CCO") identifies the compliance risks to which the establishment is exposed in the course of its business and assesses their significance and possible consequences.
- On the basis of this classification, the Compliance Officer establishes their control plan, thereby enabling efficient use of the compliance function's resources.
- The CCO ensures that compliance risk is identified and assessed before the institution enters into a new type of activity, product, or business relationship, as well as during the development of operations and a group's network on an international scale ("New Product Approval Process").
- The "New Product Approval Process" must ensure that any new product remains consistent with the guiding principles established by the Board of Directors, with the risk strategy, the institution's risk appetite, and the corresponding limits.
The Chief Internal Auditor ("CIA")
- The Chief Internal Auditor ("CIA") must formalise a three-year plan covering all matters of prudential interest (including observations and requests from the CSSF).
- The CIA also takes into account anticipated developments and innovations, as well as the risks that may arise from them.
- This plan is discussed with authorised management and the audit committee where applicable, and finally approved by the Board of Directors.
- It is acceptable for the operational tasks of the internal audit function to be outsourced by small institutions with a low and non-complex risk profile. Such outsourcing is not acceptable in principle for institutions that have branches, sub-branches or subsidiaries.
- The organisation's board of directors retains ultimate responsibility for the outsourcing of internal audit operational tasks.
C. Risk Management
Healthy Risk Culture
- The concept of "Sound Risk Management" is introduced by Circular CSSF 20/758.
- The risk policy, which implements the strategy defined by the board of directors regarding risks, must include measures to promote a healthy risk culture.
Environmental, Social, and Governance ("ESG") Risks
- The establishment's business strategy must be defined in compliance with the establishment's long-term financial interests, its solvency, its liquidity position and its risk appetite.
- The development and maintenance of a sustainable business strategy requires the consideration of all material risks, including Environmental, Social and Governance ("ESG") risks.
- Taking ESG risk factors into account would ensure the viability of the business strategy.
Subcontracting
- Any outsourcing of activities, whether tangible or intangible, including that carried out within the group to which the establishment belongs, shall be part of a written policy requiring approval from authorised management and re-approved at regular intervals by the board of directors.
- The organisation must retain the necessary expertise to effectively monitor outsourced services or tasks and the management of risks associated with outsourcing.
- The contracting establishment bases its decision to subcontract on a prior and thorough analysis, demonstrating that it does not lead to the relocation of central administration.
- The analysis will include a detailed assessment (due diligence) of the proposed service provider.
- Outsourcing does not release the establishment from its legal and regulatory obligations or its responsibilities towards its customers. It does not result in any delegation of responsibility from the establishment to the subcontractor.
- Particular attention must be paid to the following subcontracts:
- Critical activities at which the occurrence of a problem could have a significant impact on the institution's ability to comply with regulatory requirements, or even to continue its operations.
- Risks of concentration and dependence that arise when large parts of important activities or functions are outsourced to a single provider for a prolonged period.
- Continuity and the revocable nature of subcontracting. The establishment must be able to maintain its critical functions in the event of exceptional events or crises.
- Subcontracting agreements must comprise:
- Notice of termination of sufficient duration to allow the establishment to take the necessary measures to ensure the continuity of subcontracted services.
- No termination or cessation of services clause due to the application of resolution or recovery measures or insolvency proceedings to the establishment.
Discover our other publications:

Uncategorised
AMLA: the new European authority at the heart of AML/CFT supervision
Scope, governance, KYC due diligence, beneficial ownership, suspicious activity reports, and cash payments: the key contributions of the AMLR.
15 July 2026

Uncategorised
AMLR: The European regulation to be directly applicable from 10 July 2027
Scope, governance, KYC due diligence, beneficial ownership, suspicious activity reports, and cash payments: the key contributions of the AMLR.
15 July 2026

Uncategorised
AMLD6: How Directive (EU) 2024/1640 is reorganising the European AML/CFT framework
Discover the role of AMLD6, its transposition timeline, and its consequences for the FIUs, registries, supervisors and obliged entities.
15 July 2026