Skip to content
CSSF · Luxembourg

Circular CSSF 26/906 — internal governance and central administration for Luxembourg payment and e-money institutions

Fintech Passport
August 13, 2026 · 12-min read
Circular CSSF 26/906 — internal governance and central administration for Luxembourg payment and e-money institutions

Circular CSSF 26/906 replaced the internal-governance rulebook for every Luxembourg payment institution and electronic money institution, and it started applying on 30 June 2026 — so the first compliance attestation under it is already a live filing obligation. It consolidates four older texts and does more than restate them: it fixes numeric proportionality triggers, names the safeguarding controls the CSSF expects to see running daily, and creates a signed annual attestation from the whole management body. This walks through the scope, the proportionality mechanics, the safeguarding chapter and the three things Chapter 9 adds to the annual filing pack.

1. What the circular is, and what it replaced

Circular CSSF 26/906, dated 20 January 2026, is addressed to all payment institutions and electronic money institutions and is titled “Central administration, internal governance and risk management”. Its legal anchors are Articles 11(2) and 24-7(2) of the amended Law of 10 November 2009 on payment services (the LPS), which require robust internal governance: a clear organisational structure with well-defined lines of responsibility, effective risk processes, and adequate internal control mechanisms.

Circulars IML 95/120, IML 96/126, IML 98/143 and CSSF 04/155 are repealed for payment and electronic money institutions, and Circulars CSSF 11/510 and CSSF 11/520 are amended. The circular also takes account of EBA/GL/2017/09 on the information to be provided for authorisation of these institutions and registration of AISPs under Article 5(5) of Directive (EU) 2015/2366.

One boundary matters for planning. The CSSF calls 26/906 a first step towards a consolidated compilation and says expressly that it does not cover every area of concern — ICT risk management and major-incident notification are handled elsewhere. It is the governance spine the ICT, outsourcing and AML texts hang off, not a single-source rulebook.

2. Who is caught — including the passported branch

Paragraph 2 sets three limbs. The circular applies to payment and electronic money institutions whose home Member State is Luxembourg, including their branches; to Luxembourg branches of such institutions whose home Member State is outside the EEA; and to account information service providers, which come in through Articles 48-1a and 8(1)(e) of the LPS and are treated as payment institutions with proportionality applied.

The fourth case is the one firms misread. A Luxembourg branch of an EEA-authorised institution is outside the circular’s direct scope — but for the areas where the CSSF retains oversight as host authority, notably AML/CFT measures and redress procedures, that branch “shall implement central administration and internal governance arrangements as well as a risk management which are comparable to those specified in this circular”. Comparable, not exempt.

Facts: a payment institution authorised in another EEA state runs a Luxembourg branch with local staff, local customers and a local complaints inbox. Its group framework was written to the home supervisor’s rulebook, and the branch reads 26/906 as inapplicable.

What the rule says: paragraph 2 requires comparable arrangements in the host-retained areas, and AML/CFT and redress sit inside them. Luxembourg complaint-handling duties run through Circular CSSF 17/671 independently.

What the practitioner does: runs a gap analysis of the group framework against 26/906, limited to AML/CFT and redress, and documents the comparability conclusion. The deliverable is a mapping table, not a second framework — but its absence is what a host-authority review finds first.

3. Proportionality now has numbers

Paragraph 3 keeps proportionality bidirectional: some institutions must build enhanced arrangements — additional specialised committees, extra members on either body — while smaller and simpler ones may apply it downward. What is new is that the CSSF lists the criteria and attaches figures to several:

  • the risks and complexity of products and services, in particular anything beyond payment or e-money services — foreign exchange, credit granted in connection with payment services, or several financial-sector authorisations held at once;
  • the volume of payment and electronic money operations, with EUR 10 billion as the reference point, and size in turnover and balance sheet total, with EUR 0.5 billion;
  • staff numbers, with 50 persons flagged, and the distribution network — more than one branch, or a network of agents, distributors or representative offices;
  • group size, outsourcing complexity, and the structure of the IT architecture.

Paragraph 4 turns the assessment into an artefact: institutions shall document their proportionality assessment in writing and have the conclusions approved by the supervisory body at least annually. A board-approved document on a yearly refresh cycle, not a paragraph in a policy.

4. Central administration and the two bodies

Articles 11(1) and 24-7(1) of the LPS put the central administration and registered office in Luxembourg. Paragraphs 5 to 7 spell out what that excludes: an institution may not limit itself to a legal registered office, and must have its decision-making centre and administrative centre there. The decision-making centre includes the supervisory body and at least two members of the management body empowered to effectively determine the direction of the activity, plus the heads of the internal control, commercial, administrative, IT and operational functions. Outsourcing does not dissolve this, without prejudice to Circular CSSF 22/806 on outsourcing.

“Supervisory body” is used functionally — generally the Board of Directors, but whatever body controls the management under the institution’s legal form — and “management body” means the authorised managers referred to in Articles 8(1)(i) and 24-4(i) of the LPS. Paragraph 13 gives the supervisory body overall responsibility and requires it, after hearing the management body and the heads of the control functions, to approve in writing the business strategy and programme of activities, the risk strategy with risk appetite and — where credit is granted under Article 10(3) — credit risk and its limits, and the guiding principles on safeguarding of funds under Articles 14 and 24-10.

Paragraphs 46 and 47 add the remediation machinery: corrective measures follow a written procedure approved by the supervisory body, and where the CSSF has requested the measures, delays are notified to the supervisory body and to the CSSF.

5. Three functions, two of them always

The internal control functions are compliance, internal audit and risk management. Paragraph 113 requires compliance as the second line of defence and internal audit as the third, as two distinct functions. A risk control function, where established, also sits in the second line — and it is not automatic: paragraph 162 says the CSSF may request certain institutions, by reference to proportionality, to set one up. Every institution nonetheless runs an ICT and security risk framework under Regulation (EU) 2022/2554.

Paragraph 117 makes independence concrete: control-function staff may not be responsible for tasks they control, their remuneration may not track the performance of the activities they control, the function may not sit inside or report hierarchically to the business units it controls, and its head may not be subordinated to the person responsible for the controlled activity. Paragraph 116 gives the heads direct access to the supervisory body or its chair, to specialised committees, to the réviseur d’entreprises agréé — and to the CSSF. Paragraph 125 extends their scope to activities run through agents, distributors and representative offices.

Each function produces, at least annually, a summary report on its activities and functioning (paragraph 129). Paragraph 134 requires an opinion on the state of the control area as a whole, comment on resource adequacy, and submission to the supervisory body for approval and the management body for information. Paragraph 149 makes the Chief Compliance Officer particularly responsible for ensuring AML/CFT is reflected in effective, risk-appropriate controls — where this circular meets the Luxembourg CRF and goAML filing chain.

6. The New Product Approval Process, and its hard stop

Sub-chapter 7.3 scopes the process to new activities in products, services, markets, systems, processes or customers, plus material changes to them and exceptional transactions. The issues it must address include regulatory compliance, safeguarding of user funds, accounting, pricing models, impact on risk profile, capital adequacy and profitability, and whether the firm has the tools and technical knowledge to monitor the risks.

The division of labour is explicit. The requesting business unit issues the risk analysis; the management body and, where it exists, the risk control function carry out a prior, objective and comprehensive analysis across scenarios; the compliance function analyses compliance risk in advance. Then paragraph 199: no new activity may be undertaken before the management body has approved it, after hearing the control functions, and before the resources are actually available. Paragraph 200 lets the control functions require that a change be deemed material and run through the process.

7. Safeguarding: daily by default

Chapter 8 is the most operational part of the circular. The baseline (paragraph 201) is that the institution must identify all users’ funds clearly and precisely at all times, with a response capability if a safeguarding counterparty revokes its contract.

Paragraph 202 requires processes for controlling executed transactions and for reconciling funds received against information from the counterparties holding them, under procedures naming who owns each process and the escalation route. It also requires the institution to appoint a member of the management body responsible for oversight of the safeguarding control processes, and the mechanisms must identify at any time and without delay any funds not protected in one of the ways Articles 14 and 24-10 allow. Paragraph 203 sets the cadence: given the volume or complexity of transactions, those mechanisms “must be based on the implementation of daily controls and reconciliations”. Weekly is available only on a justified, documented risk analysis validated by the management and supervisory bodies, with four-eyes review.

Facts: an electronic money institution reconciles its segregation accounts weekly, on the reasoning that e-money float moves slowly and the credit institution’s statement arrives once a week.

What the rule says: daily is the default, and weekly requires a documented risk analysis validated by both bodies. Paragraph 204 separately restricts access to accounting entries, extra-accounting systems and signature powers over user funds to need-to-know and least-privilege, under four eyes and the formal responsibility of at least one management-body member.

What the practitioner does: moves to daily reconciliation, keeping weekly only where the risk analysis exists, is validated and is dated. Where counterparty data is the constraint, the fix is the reporting frequency in the account agreement — not the control frequency.

Three further points bear on contracts. Segregation accounts are opened in the institution’s own name solely for the benefit of users, and where the credit institution offers no dedicated segregation contract, explicit written and signed confirmations must be obtained instead (paragraphs 206–207). Funds must never be commingled with those of other persons, with fees and commissions flagged as a specific case (paragraph 210). And agents, distributors and branches transfer nothing — responsibility stays with the institution (paragraph 209).

8. Chapter 9: what you now file, and by when

Paragraph 218 adds three annual deliverables to those already owed under Circular CSSF 15/614 on documents to be submitted after the financial year closes.

DeliverableBasisSigned byDeadline
Annual ICT and security risk assessmentArticle 105-1(2) LPS and the amended Circular CSSF 25/880 on PSU relationship management and PSP ICT assessmentValidated by the management body — at least the member responsible for the ICT functionPer the CSSF campaign; the financial-year-2025 campaign opened 9 February 2026
Annual attestation of compliance with the circularParagraph 71All members of the management bodyAs soon as possible, at the latest the last day of the third month after financial year-end
Summary reports of the compliance and internal audit functionsParagraph 129Chief Compliance Officer and Chief Internal Auditor respectivelySame deadline; drawn up in French, German or English

The PSP ICT assessment runs on a standardised CSSF form submitted through the dedicated eDesk procedure “PSD2 – PSP ICT Assessment”, or pre-filed through the API (S3) route. The periodic prudential tables sit on a separate calendar — the subject of our note on legal reporting for Luxembourg payment and electronic money institutions.

Facts: an institution with a 31 December year-end reaches March and finds that its proportionality assessment was never formally approved by the board, and that the safeguarding oversight role was never assigned to a named management-body member.

What the rule says: paragraph 71 offers no “substantially compliant” option — either the single sentence is signed, or it becomes a reservation naming the gaps, and either way it is due by the last day of the third month.

What the practitioner does: files the reservation with both items named and dated remediation steps, then closes them before the next cycle. A reservation filed on time is a supervisory conversation; a clean attestation that is not true is a different problem.

9. FAQ

When did Circular CSSF 26/906 start to apply, and what does it replace?

It applies from 30 June 2026 under paragraph 219, and is dated 20 January 2026. Circulars IML 95/120, IML 96/126, IML 98/143 and CSSF 04/155 are repealed for payment and electronic money institutions; Circulars CSSF 11/510 and CSSF 11/520 are amended.

Does it apply to an account information service provider?

Yes — through Articles 48-1a and 8(1)(e) of the LPS, treated as payment institutions with proportionality applied. The circular names AISPs as its own example of downward proportionality.

Does it apply to a Luxembourg branch of an EEA payment institution?

Not directly, but for the areas where the CSSF retains host-authority oversight — notably AML/CFT and redress procedures — such a branch must implement arrangements comparable to those in the circular.

Is a separate risk control function mandatory?

Not for every institution. Paragraph 162 allows the CSSF to require certain institutions to establish an independent, permanent risk control function by reference to proportionality; where one exists it sits in the second line alongside compliance.

How often must safeguarding accounts be reconciled?

Daily is the default under paragraph 203. Weekly reconciliation is possible only on a justified, documented risk analysis validated by both the management and the supervisory bodies, with four-eyes review.

10. What to do, today

  • Board secretary: put the proportionality assessment on the supervisory body’s agenda as a standing annual item. Paragraph 4 makes the document, not the judgement, the deliverable.
  • Authorised management: name the management-body member responsible for oversight of the safeguarding controls under paragraph 202 and record the appointment. It is a single-person accountability the circular creates explicitly.
  • Finance and operations: test whether reconciliation is genuinely daily and four-eyed, and whether counterparty data arrives daily to support it.
  • Compliance and internal audit: check the summary report against paragraphs 129 and 134 — prior-year open exceptions, an opinion on the control area as a whole, resource adequacy — and confirm it goes to the supervisory body for approval, not just for noting.
  • Whoever owns the filing calendar: put the paragraph 71 attestation, the two summary reports and the PSP ICT assessment on one page against the third-month deadline, and settle the reservation question early.

Related: EMI licence in Luxembourg (CSSF) · PI licence in Luxembourg (CSSF) · Complaints and conduct reporting in Luxembourg · Outsourcing under Circular CSSF 22/806 · Safeguarding compared across the EU

Related reads.