One Constellation
Regulatory News

CSSF Enforcement and 2026 Supervisory Priorities Point at the Same Weaknesses

The CSSF has continued to impose penalties following AML/CFT on-site inspections, with findings centring on customer due diligence and transaction monitoring. Those are the same areas named in its supervisory priorities for 2026 — which makes the enforcement record a reasonably direct statement of what inspectors will test next.

Published: September 2026 Section: News Read time: ~5 minutes
In Brief
Recent CSSF administrative penalties have followed on-site AML/CFT inspections, with deficiencies identified in customer due diligence and transaction monitoring controls. Separately, the CSSF has set out supervisory priorities for 2026 covering asset valuation and NAV calculation, cyber security, artificial intelligence, costs and fees, ESG, tax, and AML/CFT systems. Read together, the message is consistent: the supervisor is testing whether controls operate, not whether they are documented — and the penalties are modest in amount but public in effect.

Luxembourg supervision has a particular character. Penalty amounts are often small relative to the firms involved, which can lead to them being read as minor. That misreads the mechanism: the reputational and remediation cost of a published finding, in a market built on fund domiciliation, substantially exceeds the fine.

What is more useful than the amounts is the pattern in the findings.

The Recurring Findings

Across recent AML/CFT enforcement the same deficiencies appear:

  • Customer due diligence gaps — incomplete files, identification without adequate verification, and beneficial ownership left unresolved where the structure is complex.
  • Transaction monitoring weaknesses — scenarios that do not reflect the firm’s actual risk profile, or alerts closed without recorded reasoning.
  • Sanctions control failures — screening scope or matching configuration that does not cover the parties it should.

None of these are exotic. They are the core obligations, failing in operation rather than in design.

What "AML/CFT Systems" Means as a Priority

Naming AML/CFT systems — rather than policies — as a supervisory priority is a deliberate framing. It directs attention to whether the tooling does what the policy claims:

  • Does the risk model actually differentiate, or does most of the book sit in one band?
  • Are monitoring scenarios calibrated to this firm, or inherited defaults?
  • Can an alert’s full lifecycle — trigger, investigation, reasoning, decision — be reconstructed from the record?
  • Is screening applied to beneficial owners and connected parties, or only to the named client?

The last is a frequent and specific failure. See PEP categories and RCAs for how far the screening population actually extends.

Preparing for an Inspection

The most reliable preparation is to test yourself the way an inspector would rather than against your own procedures. Sample from the full population weighted toward high risk, not conveniently. Rebuild a handful of closed alerts end to end and ask whether the reasoning is recoverable. Take a complex fund structure and check whether the ownership chain resolves today, not as at onboarding.

Our guides to examination preparation and the internal audit checklist set out that testing in detail.

Controls That Hold Up on Inspection

Risk-based CDD with resolved ownership, monitoring calibrated to your actual profile, and a case record that reconstructs the reasoning behind every decision — not just the outcome.

Examination Preparation → EU AML Framework All News
Scroll to Top