CSSF Enforcement and 2026 Supervisory Priorities Point at the Same Weaknesses
The CSSF has continued to impose penalties following AML/CFT on-site inspections, with findings centring on customer due diligence and transaction monitoring. Those are the same areas named in its supervisory priorities for 2026 — which makes the enforcement record a reasonably direct statement of what inspectors will test next.
Luxembourg supervision has a particular character. Penalty amounts are often small relative to the firms involved, which can lead to them being read as minor. That misreads the mechanism: the reputational and remediation cost of a published finding, in a market built on fund domiciliation, substantially exceeds the fine.
What is more useful than the amounts is the pattern in the findings.
The Recurring Findings
Across recent AML/CFT enforcement the same deficiencies appear:
- Customer due diligence gaps — incomplete files, identification without adequate verification, and beneficial ownership left unresolved where the structure is complex.
- Transaction monitoring weaknesses — scenarios that do not reflect the firm’s actual risk profile, or alerts closed without recorded reasoning.
- Sanctions control failures — screening scope or matching configuration that does not cover the parties it should.
None of these are exotic. They are the core obligations, failing in operation rather than in design.
What "AML/CFT Systems" Means as a Priority
Naming AML/CFT systems — rather than policies — as a supervisory priority is a deliberate framing. It directs attention to whether the tooling does what the policy claims:
- Does the risk model actually differentiate, or does most of the book sit in one band?
- Are monitoring scenarios calibrated to this firm, or inherited defaults?
- Can an alert’s full lifecycle — trigger, investigation, reasoning, decision — be reconstructed from the record?
- Is screening applied to beneficial owners and connected parties, or only to the named client?
The last is a frequent and specific failure. See PEP categories and RCAs for how far the screening population actually extends.
Preparing for an Inspection
The most reliable preparation is to test yourself the way an inspector would rather than against your own procedures. Sample from the full population weighted toward high risk, not conveniently. Rebuild a handful of closed alerts end to end and ask whether the reasoning is recoverable. Take a complex fund structure and check whether the ownership chain resolves today, not as at onboarding.
Our guides to examination preparation and the internal audit checklist set out that testing in detail.
Controls That Hold Up on Inspection
Risk-based CDD with resolved ownership, monitoring calibrated to your actual profile, and a case record that reconstructs the reasoning behind every decision — not just the outcome.
