Internal audit · Outsourcing · Luxembourg
Outsourced internal audit in Luxembourg: turning it into an asset
Many financial centre entities outsource all or part of their internal audit to an external provider. This is a pertinent response to a lack of resources or expertise — provided they understand what the Luxembourg framework permits, and manage the relationship so that it genuinely serves the board of directors and authorised management.
Why outsource your internal audit?
The reasons are concrete and legitimate. Many entities — in particular, modestly sized structures — do not have the headcount to maintain a full in-house internal audit team. Others are looking for specialised expertise that is difficult to recruit: cybersecurity, IT and resilience (DORA), anti-money laundering (AML/CFT), and data. Outsourcing also brings a fresh perspective and independence from internal teams. Finally, it makes it possible to adjust resources to activity levels without bearing the cost of a permanent structure.
What the Luxembourg framework permits (and what it does not permit)
This is the point that every manager should bear in mind. In Luxembourg, CSSF Circular 22/806 on outsourcing (amended in 2025) lays down a clear rule: for internal control functions, including internal audit, only operational tasks may be outsourced to a service provider. However, responsibility for the function itself cannot be outsourced: it remains with the organisation.
Specifically, the entity must internally designate a person responsible for the internal audit function, and the authorised direction (the managers approved by the CSSF) remain fully responsible, including for what is outsourced. Furthermore, the outsourcing of a critical or important function is subject to prior notification to the CSSF. In other words: you can delegate execution, never responsibility.
The safeguards provided for by the CSSF
The framework precisely defines the relationship with the service provider in order to preserve independence and quality:
- The service provider reports to the member of the management body responsible for the internal control function.
- For the internal audit, he must furthermore to have direct access to the governing body in its supervisory capacity — the board — or, where applicable, to the chair of the audit committee.
- He carries out his work in accordance with the organisation’s audit plan, documents each assignment and submits a report to the relevant internal manager, senior management and, where applicable, the audit committee.
These requirements are not merely administrative red tape: they ensure that the service provider works for the board, and not solely for operational management.
How to turn it into a real asset for the board and authorised management
Adhering to the framework is necessary, but not sufficient to create value. A few principles make the difference between a useful externalised audit and a mere formality:
- Keep control in-house. The designated lead must understand the subjects, drive the audit plan and challenge the provider — not just relay them. The plan remains that of the entity, based on its risks.
- To ensure that direct access to the council is effectively enabled. This access, provided for by regulations, is the best guarantee of independence: it must be used, not left on paper.
- Choose a service provider who is familiar with the sector and Luxembourg regulations. Technical expertise without an understanding of the CSSF context misses the point.
- Avoid conflicts of interest. The service provider should not audit an activity which it also advises on or carries out for the entity.
- Require reporting that supports decision-making. A clear opinion, a root-cause analysis, follow-up on recommendations — going beyond simple observation.
- Managing the relationship over the long term. Outsourced auditing is a partnership to be managed, not a one-off compliance purchase.
ARCAD, an independent firm based in Luxembourg, provides outsourced internal audit, ongoing audit and specialist audits (IT/DORA, AML/CFT), in accordance with the CSSF framework.
References & further reading
- CSSF Circular 22/806 on outsourcing (as amended by CSSF Circular 25/883) — section relating to the outsourcing of internal control functions.
- Global Internal Audit Standards, Institute of Internal Auditors (IIA), 2024.