CSSF Activity Report 2021
Investment Fund Managers (IFM)
- 08/09/2022 : Publication of the CSSF's 2021 activities and initiatives report
The CSSF has published its report on the activities and initiatives undertaken during 2021.
In this document, she revisits the weaknesses identified during her audits of Investment Fund Managers («IFMs»), the regulatory texts put in place, and the targeted issues for future years.
I - Governance and functioning of the CSSF
The CSSF aims to use its IT systems to support the development of sustainable finance through its «CSSF Strategy 4.0». Financial actors must integrate an ESG approach into their business model to develop talent and embrace the digital revolution. This strategy involves improving IT efficiency:
- By digitising exchanges with industry: more standardisation, speed, transparency and security.;
- By automating and robotising analyses except in cases of discrepancies with the standard;
- Aggregating and analysing the data to present it qualitatively to partners.
The CSSF does not intend to treat financial innovation and sustainable finance as two separate entities. The impacts and interdependencies of both must be taken into account when establishing and implementing the rules surrounding them. The benefits and risks arising from financial innovation must be analysed with consideration for the objectives pursued by sustainable finance, supported by a robust internal governance framework for projects involving virtual assets that take sustainability criteria into account.
II - Information system monitoring: IT resilience
The European regulation has proposed the «Digital Operational Resilience Act» (DORA) aimed at developing a single regulatory and supervisory framework for digital resilience in the financial sector. The proposed measures cover information and communication technology (ICT) governance, ICT risk management, a harmonised ICT incident notification process, digital operational resilience testing (advanced penetration testing, cyber attack simulations, etc.), ICT third-party service provider risk management, and information sharing. The entry into force of this text is estimated for the end of 2022.
Regarding the CSSF's expectations and practices concerning IT outsourcing, the CSSF has published Circular CSSF 22/805, replacing the prior approval requirement with a prior notification for material IT outsourcing. The CSSF has also finalised Circular CSSF 22/806, which entered into force on 30 June 2022 and concerns outsourcing, consolidating the CSSF's expectations regarding all types of outsourcing, including IT outsourcing.
III - Monitoring of GFI and OPC
III.1. Environment, Social and Governance (ESG)
Regulation (EU) 2020/852 on the establishment of a framework to facilitate sustainable investment (the 'Taxonomy Regulation') entered into force on 1 January 2022 for the environmental objectives of climate change mitigation and climate change adaptation. A press release from the CSSF was published on the way forward and a procedure to facilitate the update of pre-contractual documentation for existing UCITS and AIFs. The obligations incumbent upon investment funds concerning the Taxonomy Regulation for other environmental objectives, namely
- (i) the sustainable use and protection of aquatic and marine resources,
- (ii) the transition to a circular economy,
- (iii) the prevention and reduction of pollution, and
- (iv) the protection and restoration of biodiversity and ecosystems, shall enter into force on 1 January 2023.
The compliance of AIFM and investment funds with the various levels of EU legislation in the field of sustainable finance is a supervisory priority for the CSSF. The technical standards adopted by the European Commission in April 2022, which are currently being examined by the Council and the European Parliament, should in principle enter into force on 1er January 2023.
III.2. Operationalisation of the long-form report reform
Following the publication of CSSF circulars 21/788, CSSF 21/789, and CSSF 21/790 concerning GFIs and UCIs, the CSSF will continue its work on the long-form report reform in 2022. This work particularly concerns the integration of the new reports introduced by these circulars into risk-based prudential supervision practices, as well as monitoring the practical implementation of the new provisions with the industry and REAs.
III.3. Weaknesses identified within internal control functions
The CSSF noted shortcomings concerning internal control functions, with a predominance for the risk management function. Additional deficiencies were noted in 2021 regarding crisis simulation.
The CSSF also noted that some AIFMs do not involve themselves sufficiently in the valuation of the securities portfolios of the funds under management, specifically when these contain securities for which no market price is available. In this respect, the CSSF reminds that all AIFMs must be able to demonstrate that the portfolios of the managed funds have been valued accurately.
The CSSF also noted that the control plan for the Compliance function of certain GIIS does not allow for a correct overview of the activities effectively controlled and the risk assessed for each activity.
III.4. Deficiencies relating to the supervision of delegated activities
As part of on-site inspections dedicated to the governance of GIIs, the CSSF noted deficiencies in the supervision of delegates, and particularly in the monitoring of intermediaries responsible for marketing. Consequently, several GIIs had not implemented a supervision mechanism that was appropriate and proportionate to the size of their distribution network.
The CSSF also identified shortcomings concerning the completeness and accuracy of policies and procedures within several IFs. Some IFs do not update their policies and procedures to reflect changes in their business activities. As such, the CSSF reiterates that the utmost care must be taken in drafting and updating the procedures manual, which is an essential element for ensuring the proper functioning of the IF.
III.5. Weaknesses identified during Corporate Governance audits«
The most significant weaknesses at the board and committee level concern deficiencies relating to the definition and implementation of guidelines governing the appointment, initial and ongoing evaluation, and succession of supervisory board members, the management of actual and potential conflicts of interest, and more broadly, the responsibilities that fall to the supervisory board.
Gaps in the functioning and responsibilities assigned to authorised management and management committees were also noted, particularly regarding the formalisation and communication of management decisions or the internal governance framework, as well as the implementation of issued recommendations. Potential and confirmed conflicts were also identified by the CSSF in the allocation of responsibilities of authorised directors and are not systematically centralised by the Compliance function.
Weaknesses relating to the definition, approval, and implementation of the remuneration policy or business strategies of the inspected entities were also identified. In 2022, the CSSF planned to assess gender pay gaps within the management bodies of the supervised entities.
It was also found that certain charters and compliance policies were incomplete regarding roles and responsibilities towards management bodies and their branches. In some cases, the control programmes of the Compliance function were also incomplete or did not take into account the assessment of compliance risks. Deficiencies and delays in the execution of plans, the monitoring of weaknesses, or the content of reports were observed. Furthermore, a register of standards and regulations had not been systematically established, making the coverage of all compliance risks incomplete.
Further shortcomings were observed in the definition and completeness of risk appetite and limit indicators, as well as shortcomings relating to the independence and objectivity of certain members of the internal audit function, and deficiencies in the follow-up of corrective measures by the internal audit function. Some internal audit plans are incomplete or developed without considering a risk-based approach. Finally, there are issues concerning the scope of work carried out, the completeness of weaknesses identified, and the transmission of correct and relevant information to governance bodies.
III.6. Weaknesses identified during the «Business Model & Profitability Assessment» checks»
The weaknesses identified related to the absence of risk analysis in the context of launching new products and activities, or a reliance on group analyses without considering the local context.
Discrepancies have been observed between the business plan and the institution's strategy, with in some cases a deviation from or over-reliance on group strategies. More broadly, a lack of documented strategy definition has resulted in weaknesses in the involvement of certain functions, a lack of definition of management's role, or the absence of target indicators.
III.7. Weaknesses identified during «IT Risk» inspections»
Gaps have been identified concerning IT security, particularly the management of outdated information systems and their configurations to protect them from malicious events, control of privileged access, management and remediation of critical vulnerabilities, and monitoring of IT security-related events.
Other identified shortcomings relate to the inventory of IT assets and IT incident management, non-compliance with PSD2, low/no IT risk coverage, overall business continuity, incomplete or inconsistent IT strategies and the contractual aspect, as well as operational monitoring of IT outsourcing.
IV - Weaknesses and LBC/FT Regulations
IV.1. Weaknesses noted
A lack of checks to ensure the effectiveness of name matching tools used by professionals was noted. This issue would have allowed certain shortcomings to be identified, such as delays in updating official lists or a «name matching» issue.
Furthermore, weaknesses have been identified concerning the measures in place to identify the presence of clients within negative press articles, such as OpenLux, FinCen Leaks, and even the Pandora Papers in 2021.
Failures to apply enhanced due diligence measures to clients or intermediaries presenting risk factors were noted, as were delays in the regular periodic review of clients and shortcomings concerning the obligation to report any suspicion of money laundering/terrorist financing to the CRF.
In the collective management sector, further weaknesses have been identified concerning risk assessment, work carried out by the compliance officer, KPIs allowing AIFMs to continuously monitor activities delegated to registration and transfer agents, and shortcomings in the monitoring and control of fiscal risks related to securities lending activities.
IV.2. Modifications to the AML/CFT regulatory framework
On 20 July 2021, the European Commission published four reform proposals to strengthen AML/CFT. These proposals concern:
- the establishment of a new European AML/CFT authority (AMLA) with specific tasks and powers;
- a draft directive aiming to transpose into national law rules relating to national supervisory authorities and CRFs;
- a draft regulation containing directly applicable AML/CFT rules within Member States concerning customer due diligence and beneficial ownership
- a review of EU Regulation 2015/847 on payment services to extend its scope to crypto-asset transfers.
In addition to these proposals, the EBA published its “Opinion on the risks of money laundering and terrorist financing affecting the European Union’s financial sector,” analysing risks related to virtual currencies, services provided by FinTech companies, weaknesses in AML/CFT systems and controls, tax crimes, and the COVID-19 pandemic.
At the Luxembourg framework level, a few minor adoptions were made via the law of 25 February 2021 amending the law of 12 November 2004 on AML/CFT, the law of 25 March 2020 instituting a register of payment and bank accounts identified by an IBAN number, and the law of 10 July 2020 instituting a register of trusts and fiduciary arrangements.
Several CSSF circulars have been adopted:
- The CSSF circular 21/788 providing guidelines for the collective investment sector on the requirement for an AML/CFT report to be prepared by an approved statutory auditor.
- The CSSF circular 21/782 on the EBA's revised guidelines on BC/FT risk factors
The CSSF has also updated the following documents:
- The Finance Ministry's code of conduct regarding the implementation of financial sanctions and its related Questions and Answers; ;
- The CSSF's FAQ on AML/CFT for individuals / investors ;
- The CSSF's Questions/Answers concerning persons involved in AML/CFT for a Luxembourg investment fund or investment fund manager supervised by the CSSF for AML/CFT purposes; ;
- CSSF Questions/Answers regarding the completion of the «AML/CFT Market Entry Form» (for investment funds and GFIs) in eDesk.
Discover our other publications:

Roadmap: building your GRC framework step by step
An effective GRC framework is built progressively, from the diagnosis of the existing state to consolidation, by adapting each step to the maturity, size and priorities of the organisation.

GRC reporting: giving the board an overview
A useful GRC reporting consolidates the work of control functions into a readable view allowing the board to identify developments, areas of concern and decisions to be made.

Data, evidence and traceability: the foundation of a credible system
A credible monitoring system relies on reliable data, structured evidence and an audit trail making it possible to reconstruct decisions and actions throughout the activity.