Remote working in the financial sector

Remote working requirements

1. Grundlagen

  • The’approval from the CSSF is not necessary to implement remote working.
  • forme de présence à domicile, de présence sur le lieu de travail, ou d'une combinaison des deux. Board of Directors' responsibility.
  • The possibility of working off-site must be planned in the Employment contract.
  • The use of remote working must not to undermine good governance and the control environment of the entity (4-eyes principle, dashboards, KPIs...).
  • The use of remote working should be in accordance with legal and regulatory provisions in force in Luxembourg and abroad (example: tax regime for cross-border commuters).
  • Circular CSSF 21/769 as amended strictly regulate the use of private equipment for carrying out remote working.
  • The Circular does not does not deal with contractual relations between supervised entities and their employees, which remain notably governed by the Convention of 20 October 2020 relating to the legal framework for teleworking.

2. Definition of teleworking according to CSSF Circular 21/769 as amended

Circular CSSF 21/769 as amended introduces Cumulative conditions for defining the concept of teleworking :

  1. The work must be provided by means of information and communication technologies (TIC) on accord preliminary of the’employer ;
  2. remote working basis voluntary base (it is advisable to obtain the express and informed consent of the employee); ;
  3. The tasks must be carried out within the framework of working hours defined and in a Predetermined place different from the employer's premises.

Any task carried out as part of BCP/DRP activation does not fall within the definition of remote working and is therefore not covered by CSSF Circular 21/769 as amended.

3. Central administration

In order to comply with the requirements for’Central administration :

  • The entity must be able to prove that its headquarters remain the decision-making centre; ;
  • At least A Responsible Person must be present at the company's registered office at any time; ;
  • The key functions must be represented face-to-face daily ;
  • The staff must be able to get to the premises of society in the most short deadlines ;
  • The name people operating in remote work environments simultaneous must be Limited ;
  • The duration remote working granted to each person must be limited ;
  • The Continuity des activités critiques doit être assured.

4. Remote working policy and risk analysis

The supervised entity must perform a Risk analysis to identify the risks inherent in the implementation of teleworking. It must also implement mitigation measures aimed at keeping residual risks within acceptable limits based on its Risk appetite (Risk Appetite). Risk analysis and the implementation of mitigation measures must be formalised and regularly reviewed by the entity.

The Board of Directors must formalise a Remote working policy which must be reviewed annually based on risk analysis. Point 32 of CSSF Circular 21/769, as amended, indicates a de minimis list that must be included in this policy.

5. Security Policy

The entity must formalise a Security policy This policy, which must be approved by the Board of Directors, defines the principles and rules applicable to teleworking in order to protect the confidentiality, integrity and availability of data, information and ICT.

The access rights Access rights granted to teleworkers must be in line with the risk analysis and security policy. These access rights must be reviewed at least annually (semi-annually for privileged users).

Furthermore, the entity must ensure that it keeps the control on the devices for remote connection to ICT systems. In this context, the use of personal devices must be restricted to low-risk activities and must be subject to specific risk analysis.

The components of the’Remote working infrastructure must, at all times, be secure and controlled. Thus, mechanisms must be put in place by the entity to detect and block any abnormal connection. Two-factor authentication must also be implemented to remotely connect to the company's ICT systems.

6. Remote Working Controls and Awareness

The entity must retain all elements permitting the control of conformity to the remote working policy and CSSF Circular 21/769, as amended. This information must be made available CSSF's disposition As requested.

The internal control functions (compliance, risk management, internal audit…) must to include The review of compliance with the requirements relating to teleworking within their Multiannual work plans. Furthermore, the Reports synthèse annuelle doit to include elements Statistics on the use of remote working as well as a mention of the Incidents significant ones that have taken place.

The Good functioning of the communication channel between the remote device and the company's infrastructure as well as the’effectiveness of security measures implementations must be audited by an independent security control function (Information security officer, internal audit or specialised external third party) before the launch of remote working and regularly thereafter. Scan tests and penetration tests must also be carried out regularly.

Furthermore, the entity must implement a Journalisation in order to ensure that all connections and technical information relating to remote working are recorded for security audit purposes.

The Staff awareness The risks and best practices associated with remote working must also be ensured by the entity through periodic training, newsletters or other communications.

7. Modifications introduced by CSSF Circular 22/804

The date of’entry into force of CSSF Circular 21/769 as amended is set at 1 July 2022.

The concept of «normal general working conditions» has been removed. The CSSF Circular 21/769 as amended so remain relevant in a situation of pandemic Or other exceptional circumstances having similar repercussions on general working conditions.

Our experts will support you

Remote working policy - Risk analysis - Compliance - Mock audit

Discover our other publications:

en_GBEnglish