Skip to content
CSSF · Luxembourg

Outsourcing under Circular CSSF 22/806 — the three-month notification and the critical-function test

Fintech Passport
August 13, 2026 · 11-min read
Outsourcing under Circular CSSF 22/806 — the three-month notification and the critical-function test

Outsourcing a critical or important function in Luxembourg requires a notification filed at least three months before it goes live — and a notification made late, or on the wrong form, counts as not made at all. Circular CSSF 22/806, as amended by Circular CSSF 25/883, is the Luxembourg outsourcing regime for banks, payment institutions, e-money institutions and other supervised entities. It sets the test for what counts as outsourcing, the test for what counts as critical or important, and a supervisory notification with a hard lead time. This walks through all three, plus the register, the exit plan and the rule that traps regulated-activity outsourcing.

1. Is it outsourcing at all?

Point 15 gives the test. In-scope entities must establish whether an arrangement with a third party falls under the definition of outsourcing, and the assessment turns on two questions: whether the function, or part of it, is performed by the service provider on a recurrent or ongoing basis; and whether that function would normally fall within the scope of functions that would or could realistically be performed by the entity itself — even if the entity has never performed it.

That second limb defeats the most common argument against classification. “We have never done this in-house and could not” is not the test; the test is whether an entity of that kind realistically could. Point 16 adds that where an arrangement covers multiple functions, all aspects must be considered together rather than assessed separately.

Point 17 then lists what is, as a general principle, not outsourcing: a function legally required to be performed by a service provider, such as the statutory audit; market information services; global network infrastructures; clearing and settlement arrangements between clearing houses, central counterparties and settlement institutions and their members; global financial messaging infrastructures subject to oversight by relevant authorities; correspondent banking services; and the acquisition of services, goods or utilities the entity would not otherwise undertake itself — professional advice, cleaning and premises maintenance, catering, clerical and travel services, plastic cards and card readers, office supplies, furniture, electricity, gas, water and telephone lines.

2. When it is critical or important

Point 18 sets three situations in which a function must always be treated as critical or important. First, where a defect or failure in its performance would materially impair the entity’s continuing compliance with the conditions of its authorisation or its other legal and regulatory obligations, its financial performance, or the soundness or continuity of its services and activities. Second, where operational tasks of the internal control functions, or of the financial and accounting function, are outsourced. Third, where credit institutions or payment institutions intend to outsource functions of banking activities or payment services to an extent that would require authorisation by the relevant competent authority.

The second limb is the one that surprises firms: outsourcing operational tasks of compliance, internal audit, risk or accounting is critical or important by definition, with no materiality assessment available.

Point 20 then lists the factors for the assessment in every other case, to be weighed together with the risk assessment: direct connection to core business activities; the potential impact of disruption on financial resilience and viability, business continuity and operational resilience, operational risk including conduct, ICT and legal risk, and reputational risk; the impact on the entity’s ability to identify, monitor and manage risks, to comply with legal requirements and to conduct appropriate audits of the function; the impact on services provided to clients; aggregated exposure to the same service provider and the cumulative impact of arrangements in the same business area; the size and complexity of the affected business area; whether the arrangement might be scaled up without revising the underlying agreement; substitutability — the ability to transfer to another provider contractually and in practice, with the risks, costs and timeframe of doing so; the ability to reintegrate the function; and data protection, including the impact of a confidentiality breach or a failure of availability and integrity, and GDPR compliance.

3. Internal control and accounting functions

Sub-chapter 4.1.3 places a structural limit. Under point 21, outsourcing arrangements of internal control functions must not effectively result in the transfer of those functions as a whole to the service provider — arrangements are limited in principle to operational tasks. Point 22 elaborates: they must not undermine the permanence or continued effectiveness of the entity’s internal control arrangements, which in practice means they must be proportionate and must not result in the effective carving out of the substance of those functions.

Point 23 requires the entity to ascertain that the service provider complies with applicable suitability requirements and has appropriate and sufficient technical knowledge and experience — and in particular that the provider can demonstrate appropriate and up-to-date knowledge of the regulatory framework applicable to the entity. A generic provider of the discipline is not enough; the provider has to know the entity’s own rulebook. Point 24 then places the provider under the oversight of, and reporting to, the person responsible for the function inside the entity.

Facts: a Luxembourg payment institution engages a firm to run its compliance monitoring plan end to end, including deciding the plan’s content, and retains a part-time officer to receive the output.

What the rule says: point 21 limits outsourcing to operational tasks and prohibits transfer of the function as a whole; point 22 prohibits carving out the substance. Deciding the monitoring plan is not an operational task, and this arrangement risks being the transfer point 21 forbids. Separately, point 18(b) makes it critical or important automatically, triggering the notification in point 59.

What the practitioner does: keeps ownership of the plan, the risk assessment and the conclusions inside the entity and outsources execution of testing, with the provider reporting to the internal function holder — and files the three-month notification rather than treating the arrangement as ordinary procurement.

4. The three-month notification

Point 59 is the operational centre of the circular. An in-scope entity that intends to outsource a critical or important function must notify its plans in advance to the competent authority, using the instructions and, where available, the forms on the CSSF website. The notification must be submitted at least three months before the planned outsourcing comes into effect. Where the entity is using a Luxembourg support PFS governed by Articles 29-1 to 29-6 of the law on the financial sector, that notice period is reduced to one month.

Then the sanction, and it is unusually blunt: any planned outsourcing arrangement which has not been notified within that period, or without using the instructions and forms available on the CSSF website, will be considered as not notified. A late filing does not become a valid filing on receipt.

Point 59 also carries a footnote obligation that is easy to miss: the entity must notify the competent authority of material changes to existing arrangements without undue delay — including where a material change makes an arrangement critical or important for the first time, or affects an already critical or important one. Point 60 confirms the notification is without prejudice to supervisory or binding measures and administrative sanctions, and that entities remain fully responsible for compliance.

SituationNotificationLead time
Critical or important function, ordinary service providerAdvance notification on CSSF instructions and formsAt least 3 months before it comes into effect
Critical or important function, Luxembourg support PFS under Articles 29-1 to 29-6 LFSSame1 month
Material change to an existing arrangement, or one becoming critical or importantNotification to the competent authorityWithout undue delay
Not critical or importantNo advance notification under point 59; register entry still required
Filed late or off-formTreated as not notified

5. Outsourcing something that would need a licence

Points 61 to 64 handle the case where the outsourced function is itself a regulated activity. Where a credit institution or payment institution outsources functions of banking activities or payment services to a provider in Luxembourg or another member state, to an extent that performing that function would require authorisation or registration if carried out in Luxembourg, the outsourcing may take place only if the provider is authorised or registered by a competent authority in that member state to perform those activities, or is otherwise allowed to carry them out under the relevant national framework.

For a provider in a third country, point 62 requires both that the provider is authorised or registered there and supervised by a competent authority, and that there is an appropriate cooperation agreement — for example a memorandum of understanding or college agreement — between the CSSF and that supervisory authority. The circular tells entities to contact the CSSF in the early planning stages to ascertain whether such arrangements are or can be put in place.

Facts: a Luxembourg payment institution plans to move transaction execution to a group affiliate in a third country, and treats it as intragroup and therefore low-risk.

What the rule says: intragroup status does not help here. Point 62 requires the affiliate to be authorised and supervised in the third country and requires a cooperation agreement between the CSSF and that supervisor to exist or be capable of being put in place. The circular also states elsewhere that intragroup outsourcing is not necessarily less risky than outsourcing to a third party.

What the practitioner does: raises the cooperation-agreement question with the CSSF before the project is committed, because it is a condition the entity cannot create itself — and builds the three-month notification into the plan on the assumption that the answer may be no.

6. The register, the documentation and the exit plan

Section 4.2.7 requires a register of all outsourcing arrangements, including those with group service providers. The recorded fields include the function outsourced, the approving body inside the entity, the governing law of the outsourcing agreement, the dates of the most recent and next scheduled audits where applicable, the names of any sub-contractors to which material parts of a critical or important function are sub-outsourced together with the country concerned, identification of alternative service providers, and whether the outsourced critical or important function supports business operations that are time-critical.

Sub-outsourcing is treated as a change in the risk, not a pass-through. The entity remains fully responsible for compliance with regulatory requirements including in the case of sub-outsourcing, must determine whether sub-outsourcing is authorised at all, and must adapt its governance and risk framework accordingly — while the initial service provider also carries monitoring obligations. Concentration risk is called out expressly: the risk from multiple arrangements with the same provider, and from outsourcing critical or important functions to a limited number of providers, must be managed.

Section 4.3.4 requires a documented exit plan for each critical or important function to be outsourced, where exit is considered possible, taking into account service interruptions and unexpected termination. Where an entity relies on a group-level exit plan, it must receive a summary and be satisfied the plan can actually be executed. Where the arrangement is also an ICT service, the DORA register and contractual requirements sit on top — see our note on the register of information. And the governance framework the circular assumes is now set out in Circular CSSF 26/906, which cross-refers to 22/806 throughout.

7. FAQ

How long before go-live must a critical outsourcing be notified to the CSSF?

At least three months, using the instructions and forms on the CSSF website — reduced to one month where the provider is a Luxembourg support PFS under Articles 29-1 to 29-6 of the law on the financial sector.

What happens if we notify late?

Point 59 states that an arrangement not notified within the period, or not notified using the required instructions and forms, will be considered as not notified. It does not become valid on receipt.

Is outsourcing the compliance function always critical or important?

Outsourcing operational tasks of the internal control functions, or of the financial and accounting function, is always critical or important under point 18(b). The function as a whole may not be transferred at all — point 21 limits arrangements in principle to operational tasks.

Is intragroup outsourcing treated more lightly?

No. The circular states that intragroup outsourcing is not necessarily less risky than outsourcing to a third party, and the register must include arrangements with group service providers.

Can we outsource a payment service to a provider outside the EEA?

Only where the provider is authorised or registered and supervised in that third country and there is an appropriate cooperation agreement between the CSSF and that supervisory authority. The CSSF should be contacted in the early planning stages.

Does buying software or cloud capacity count as outsourcing?

It depends on the point 15 test — recurrent or ongoing performance of a function the entity realistically could perform itself. Utilities, office goods and one-off professional services are generally not outsourcing; a recurring service performing an entity function generally is.

8. What to do, today

  • Run the point 15 test on the existing supplier list. The “we could never do this in-house” argument does not survive it, and unclassified arrangements are the usual finding.
  • Put the three months in the procurement gate. A signed contract with a go-live inside three months of notification is a defect at signature, not at go-live.
  • Check the register against Section 4.2.7 fields — governing law, audit dates, named sub-contractors and their countries, alternative providers, time-criticality. Most registers are missing the last three.
  • Re-examine internal control outsourcing against points 21 to 24: operational tasks only, provider demonstrating knowledge of your regulatory framework, reporting to the internal function holder.
  • For any third-country provider, ask the CSSF about the cooperation agreement before committing — it is a precondition you cannot create.
  • Write the exit plans for each critical or important function, and if you rely on a group plan, obtain the summary and test whether it is actually executable for your entity.

Related: Circular CSSF 26/906 — internal governance · DORA Article 30 ICT contract terms · The DORA register of information

Related reads.