CSSF Activity Report 2021

Specialised PSFs and Support PSFs

The CSSF has published its report on the activities and initiatives undertaken during 2021.

In this document, she looks back at the weaknesses identified during her checks on support PSFs and specialised PSFs, the regulatory texts put in place, and the objectives targeted for the coming years.

I - Governance and functioning of the CSSF

The CSSF aims to use its IT systems to support the development of sustainable finance through its «CSSF Strategy 4.0». Financial actors must integrate an ESG approach into their business model to develop talent and embrace the digital revolution. This strategy involves improving IT efficiency:

  • By digitising exchanges with industry: more standardisation, speed, transparency and security.;
  • By automating and robotising analyses except in cases of discrepancies with the standard;
  • Aggregating and analysing the data to present it qualitatively to partners.

 

The CSSF does not intend to treat financial innovation and sustainable finance as two separate entities. The impacts and interdependencies of both must be taken into account when establishing and implementing the rules surrounding them. The benefits and risks arising from financial innovation must be analysed with consideration for the objectives pursued by sustainable finance, supported by a robust internal governance framework for projects involving virtual assets that take sustainability criteria into account.

II - Information system monitoring: IT resilience

The European regulation has proposed the «Digital Operational Resilience Act» (DORA) aimed at developing a single regulatory and supervisory framework for digital resilience in the financial sector. The proposed measures cover information and communication technology (ICT) governance, ICT risk management, a harmonised ICT incident notification process, digital operational resilience testing (advanced penetration testing, cyber attack simulations, etc.), ICT third-party service provider risk management, and information sharing. The entry into force of this text is estimated for the end of 2022.

Regarding the CSSF's expectations and practices concerning IT outsourcing, the CSSF has published Circular CSSF 22/805, replacing the prior approval requirement with a prior notification for material IT outsourcing. The CSSF has also finalised Circular CSSF 22/806, which entered into force on 30 June 2022 and concerns outsourcing, consolidating the CSSF's expectations regarding all types of outsourcing, including IT outsourcing.

III - Monitoring of DFSIs

III.1. Specific regulatory modifications for support PSF:

The law of 21 July 2021 removed the fourth dash from Article 29-1, paragraph 1.er, of the law of 5 April 1993 relating to the financial sector on the activity of «mail management». Mail management giving access to confidential data presents only an operational, not a material, risk. Furthermore, Article 41 of the law of 5 April 1993 lays down the conditions under which activities relating to data subject to professional secrecy may be subcontracted to third parties. This article is sufficient to ensure adequate processing of data subject to professional secrecy, and the CSSF has therefore ruled that it is no longer necessary to stipulate an authorisation requirement for the mail management activity giving access to confidential data.

The law of 21 July 2021 also addressed the merger of the statuses of primary IT system operator (OSIP) and secondary IT system operator (OSIS), given that the distinction between the types of systems is obsolete. The importance of certain secondary systems, and the increase in IT-related operational risks due to the growing complexity and interconnection of both primary and secondary IT environments and systems, no longer justify the existence of two statuses. A transitional regime is provided for approved OSIPs and OSISs (Articles 29-3 and 29-4 of the law of 5 April 1993), so that they automatically benefit from the new status of financial sector IT and communication network operator (OSIRC) introduced by the new Article 29-3 of the law. Consequently, a new capital requirement has been put in place, increasing from €50,000 to €125,000.

In 2021, the CSSF wished to establish a systematic method for classifying support PSF according to the risks they pose to financial sector professionals in order to develop a coherent risk-based approach, by supplementing and confirming the risk profile of each PSF based on quantitative criteria, services offered, regulatory compliance and other criteria relevant to PSF activities. This classification will be reviewed annually, with further refinement of the criteria.

The CSSF has also begun a project to overhaul CSSF circulars 95/120, 96/126, and 98/143 with a view to updating and consolidating them into a single future circular detailing the CSSF's expectations regarding governance. This work will continue in 2022, in addition to a review of the framework for the annual information to be provided in the context of the closure of CSSF circular 12/544.

III.2. Weaknesses observed during « Corporate Governance » audits»

The most significant weaknesses at the level of boards of directors and their specialised committees concern deficiencies relating to the definition and implementation of the guiding principles governing the nomination, initial and ongoing evaluation, and succession of supervisory board members.

Gaps were also noted in the functioning and responsibilities assigned to authorised management and management committees, particularly regarding the formalisation and communication of management decisions or the internal governance framework, as well as the implementation of issued recommendations.

Weaknesses relating to the definition, approval, and implementation of the remuneration policy or business strategies of the inspected entities were also identified. In 2022, the CSSF planned to assess gender pay gaps within the management bodies of the supervised entities.

Shortcomings were also found in the risk management function, specifically in the definition and completeness of risk appetite and limit system indicators. In the context of outsourcing certain activities, whether internal or external to the group, deficiencies were observed in the nature, formalisation, and supervision of outsourced activities.

III.3. Weaknesses identified during «IT Risk» audits»

Gaps have been identified concerning IT security, particularly the management of outdated information systems and their configurations to protect them from malicious events, control of privileged access, management and remediation of critical vulnerabilities, and monitoring of IT security-related events.

Other identified shortcomings relate to the inventory of IT assets and IT incident management, non-compliance with PSD2, low/no IT risk coverage, overall business continuity, incomplete or inconsistent IT strategies and the contractual aspect, as well as operational monitoring of IT outsourcing.

IV - Weaknesses and LBC/FT Regulations

IV.1. Weaknesses noted

A lack of checks to ensure the effectiveness of name matching tools used by professionals was noted. This issue would have allowed certain shortcomings to be identified, such as delays in updating official lists or a «name matching» issue.

Furthermore, weaknesses have been identified concerning the measures in place to identify the presence of clients within negative press articles, such as OpenLux, FinCen Leaks, and even the Pandora Papers in 2021.

Failures to apply enhanced due diligence measures to clients or intermediaries presenting risk factors were noted, as were delays in the regular periodic review of clients and shortcomings concerning the obligation to report any suspicion of money laundering/terrorist financing to the CRF.

IV.2. Modifications to the AML/CFT regulatory framework

On 20 July 2021, the European Commission published four reform proposals to strengthen AML/CFT. These proposals concern:

  • The creation of a new European AML/CFT authority (AMLA) with specific tasks and powers; ;
  • A draft directive aiming to transpose into national law rules relating to national supervisory authorities and CRF; ;
  • A draft regulation containing directly applicable AML/CFT rules within Member States concerning customer due diligence and beneficial owners; ;
  • A revision of EU Regulation 2015/847 on payment services in the internal market, with the aim of extending its scope to include crypto-asset transfers.

 

In addition to these proposals, the EBA published its “Opinion on the risks of money laundering and terrorist financing affecting the European Union’s financial sector,” analysing risks related to virtual currencies, services provided by FinTech companies, weaknesses in AML/CFT systems and controls, tax crimes, and the COVID-19 pandemic.

At the Luxembourg framework level, a few minor adoptions were made via the law of 25 February 2021 amending the law of 12 November 2004 on AML/CFT, the law of 25 March 2020 instituting a register of payment and bank accounts identified by an IBAN number, and the law of 10 July 2020 instituting a register of trusts and fiduciary arrangements.

CSSF Circular 21/782 has been adopted on the revised EBA guidelines on BC/FT risk factors.

Discover our other publications: