Remote working in the financial sector

CSSF Circular 21/769

1. Grundlagen

  • The’approval from the CSSF is not necessary to implement remote working.
  • forme de présence à domicile, de présence sur le lieu de travail, ou d'une combinaison des deux. Board of Directors' responsibility.
  • The use of remote working must not to undermine good governance and the control environment of the entity (4-eyes principle, dashboards, KPIs...).
  • The use of remote working should be in accordance with legal and regulatory provisions in force in Luxembourg and abroad (example: tax regime for cross-border commuters).
  • The CSSF Circular 21/769 strictly regulate the use of private equipment for carrying out remote working.
  • The Circular does not does not deal with contractual relations between supervised entities and their employees, which remain notably governed by the Convention of 20 October 2020 relating to the legal framework for teleworking.

2. Definition of teleworking according to CSSF Circular 21/769

Circular CSSF 21/769 introduces Cumulative conditions for defining the concept of teleworking :

  1. The work must be provided by means of information and communication technologies (TIC) on accord preliminary of the’employer ;
  2. remote working basis voluntary base (it is advisable to obtain the express and informed consent of the employee); ;
  3. The tasks must be carried out within the framework of working hours defined and in a Predetermined place different from the employer's premises.

The work must be provided as part of the’normal company activity. Any task carried out as part of the activation of a BCP/DRP or in exceptional circumstances (such as the Covid-19 pandemic) does not fall within the definition of remote working and is therefore not covered by CSSF Circular 21/769.

3. Central administration

In order to comply with the requirements for’Central administration :

  • The entity must be able to prove that its headquarters remain the decision-making centre; ;
  • At least A Responsible Person must be present at the company's registered office at any time; ;
  • The key functions must be represented face-to-face daily ;
  • The staff must be able to get to the premises of society in the most short deadlines ;
  • The name people operating in remote work environments simultaneous must be Limited ;
  • The duration remote working granted to each person must be limited ;
  • The Continuity des activités critiques doit être assured.

4. Remote working policy and risk analysis

The supervised entity must perform a Risk analysis to identify the risks inherent in the implementation of teleworking. It must also implement mitigation measures aimed at keeping residual risks within acceptable limits based on its Risk appetite (Risk Appetite). Risk analysis and the implementation of mitigation measures must be formalised and regularly reviewed by the entity.

The Board of Directors must formalise a Remote working policy which must be reviewed annually based on risk analysis. Point 32 of CSSF Circular 21/769 indicates a de minimis list that must be included in this policy.

5. Security Policy

The entity must formalise a Security policy This policy, which must be approved by the Board of Directors, defines the principles and rules applicable to teleworking in order to protect the confidentiality, integrity and availability of data, information and ICT.

The access rights Access rights granted to teleworkers must be in line with the risk analysis and security policy. These access rights must be reviewed at least annually (semi-annually for privileged users).

Furthermore, the entity must ensure that it keeps the control on the devices for remote connection to ICT systems. In this context, the use of personal devices must be restricted to low-risk activities and must be subject to specific risk analysis.

The components of the’Remote working infrastructure must, at all times, be secure and controlled. Thus, mechanisms must be put in place by the entity to detect and block any abnormal connection. Two-factor authentication must also be implemented to remotely connect to the company's ICT systems.

6. Remote Working Controls and Awareness

The entity must retain all elements permitting the control of conformity to the teleworking policy, as well as CSSF Circular 21/769. This information will need to be updated CSSF's disposition As requested.

The internal control functions (compliance, risk management, internal audit…) must to include The review of compliance with the requirements relating to teleworking within their Multiannual work plans. Furthermore, the Reports synthèse annuelle doit to include elements Statistics on the use of remote working as well as a mention of the Incidents significant ones that have taken place.

The Good functioning of the communication channel between the remote device and the company's infrastructure as well as the’effectiveness of security measures implementations must be audited by an independent security control function (Information security officer, internal audit or specialised external third party) before the launch of remote working and regularly thereafter. Scan tests and penetration tests must also be carried out regularly.

Furthermore, the entity must implement a Journalisation in order to ensure that all connections and technical information relating to remote working are recorded for security audit purposes.

The Staff awareness The risks and best practices associated with remote working must also be ensured by the entity through periodic training, newsletters or other communications.

Our experts will support you

Remote working policy - Risk analysis - Compliance - Self-assessment questionnaire

Discover our other publications: