One Constellation
Regulatory News

CSSF Adopts AMLA Templates for AML/CFT Data Collection

The CSSF has moved its AML/CFT risk data collection onto standardised templates prepared by the EU Anti-Money Laundering Authority. For Luxembourg fund managers, administrators and payment firms this is more than a form change: it signals the shift from nationally-shaped questionnaires toward a single European supervisory dataset against which firms will be compared.

Published: September 2026 Section: News Read time: ~5 minutes
In Brief
The CSSF now collects AML/CFT risk data from supervised entities using templates prepared by AMLA, the EU Anti-Money Laundering Authority, submitted through the CSSF’s eDesk platform. Selected entities — including certain AIFMs and UCITS management companies — have also been drawn into AMLA’s own data collection exercise ahead of direct supervision. The practical consequence for firms is that AML/CFT data must now be produced in a defined structure, on a defined cadence, from systems rather than from spreadsheets — and it will be benchmarked against peers across the Union rather than read in isolation.

Supervisory reporting has historically been shaped nationally. A Luxembourg entity answered a CSSF questionnaire, an Irish entity answered a Central Bank one, and the two were not directly comparable. AMLA changes that by design: harmonised templates exist so that supervisors can compare.

That has a consequence firms sometimes miss. When data is standardised, being an outlier becomes visible — and an outlier position you cannot explain is a supervisory conversation.

What Firms Are Being Asked For

The templates gather quantitative and qualitative risk data — customer risk distribution, geographic exposure, product and channel risk, screening and alert volumes, and the outcomes of due diligence and monitoring activity. In other words, the operating metrics of the AML programme rather than a description of its policies.

Two things follow. First, the numbers have to exist. A firm that cannot say how many customers sit in each risk band, or how many alerts were generated and how they were dispositioned, has a data problem before it has a reporting problem. Second, the numbers have to be defensible, because they are now comparable.

Why This Is Harder for Fund Structures

Fund administration presents a structural difficulty that retail banking does not. The "customer" may be a fund, the investors sit behind it, the manager is a separate relationship, and the ownership chain runs through several layers and jurisdictions before reaching a natural person.

Producing a clean risk distribution across that requires the beneficial ownership picture to be resolved and current, not reconstructed at reporting time. Firms that hold investor data across multiple administration systems tend to discover this only when asked to aggregate it.

What to Do Before the Next Cycle

  • Map each template field to a system of record. Any field whose answer is assembled by hand is a field that will be inconsistent between cycles.
  • Reconcile risk ratings. If the same investor appears at different risk levels in different structures, the aggregate is indefensible — see building a defensible risk matrix.
  • Close the UBO gaps deliberately. Unresolved ownership shows up as unclassified exposure.
  • Be ready to explain outliers. A low alert rate is not self-evidently good; it may read as under-detection.

Our overview of the EU AML framework covers how AMLR, AMLD and AMLA fit together.

Reporting-Ready AML Data for Fund Structures

Resolve ownership through the structure, hold one risk rating per investor across funds, and produce the risk distribution and alert-outcome data supervisors now ask for — from the system, not a spreadsheet.

EU AML Framework → Risk Assessment Template All News
Scroll to Top