Skip to content
CSSF · Luxembourg

CSSF Regulation 12-02: the Luxembourg AML rulebook

Fintech Passport
August 24, 2026 · 9-min read
CSSF Regulation 12-02: the Luxembourg AML rulebook

Every Luxembourg AML conversation eventually lands on the same instrument, and most firms have never read it end to end. The Law of 12 November 2004 states the obligations; the Grand-ducal Regulation of 1 February 2010 details some of them. But the document telling a CSSF-supervised payment or e-money institution how to discharge them — how often to re-screen a politically exposed person, what a customer acceptance policy must contain, who signs, what internal audit owes the board each year — is CSSF Regulation N° 12-02 of 14 December 2012, as amended by CSSF Regulation N° 20-05 of 14 August 2020.

1. Where 12-02 sits in the stack

Three instruments, in order of generality. The Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended, carries the primary obligations. The Grand-ducal Regulation of 1 February 2010, as amended, details certain of its provisions. CSSF Regulation N° 12-02 then sets out the operational specification for professionals supervised by the CSSF — and it is where most supervisory findings are written, because it is the layer with testable requirements.

Read it as the answer key to the Law, not a separate regime. Almost every article opens by naming the provision of the Law it details, so a finding under 12-02 is simultaneously a finding under the Law — which is why the regulation is the right document to build a control matrix from.

2. Risk assessment: five sources, and an annual return

Article 4(1) requires the identification, assessment and understanding of risks under Article 2-2 of the Law to determine which due-diligence measures apply, based on materiality. It then names the sources a firm must incorporate into its risk-management procedures — a checklist, not a suggestion:

  • the European Commission’s supranational ML/TF risk assessment;
  • the Luxembourg national risk assessment;
  • sub-sectoral ML/TF risk assessments;
  • the joint guidelines of the three European Supervisory Authorities on ML/TF risk factors;
  • the related CSSF publications.

Two further paragraphs are easy to miss and frequently the finding. Article 4(2) requires communication means allowing the firm to provide information on its risk assessment to the CSSF. Article 4(3) requires it to be organised so as to be able to complete the annual CSSF ML/TF risk questionnaire correctly and exhaustively and submit it within the time limits, through the channel the CSSF determines — a data-architecture obligation expressed as a reporting one.

3. Customer acceptance, and the two exceptions people rely on

Article 8 requires a customer acceptance policy adapted to the firm’s activities, so that entry into a relationship is subject to prior risk identification, assessment and understanding. Article 10 requires that policy to include a specific examination and acceptance procedure for defined customer categories — a written escalation path. Article 11 requires documentation of all contact, in whatever form, the provision that makes a rejected applicant a record rather than a non-event.

Then the carve-out firms lean on most heavily — alongside Article 13, which allows an account for a company being incorporated:

  • Article 12 — a relationship may be entered into, or an account opened, before or during verification of the customer’s and beneficial owner’s identity, on three cumulative conditions: the ML/TF risk is low and efficiently managed; it is necessary not to interrupt the normal conduct of business; and verification happens at the earliest opportunity after first contact. Internal procedures must set the timeframe.

Article 14 handles occasional transactions: where one of €15,000 or more under Article 3(1)(b)(i) of the Law is carried out, identification and verification apply before the transaction, on the same terms as for a business relationship. Article 14(2) closes the gap — where it is carried out in several operations, due diligence applies at the latest when the firm recognises the aggregate has reached the threshold, and firms must have procedures or systems allowing them to detect that. That is an explicit systems obligation no per-transaction control can satisfy.

4. Enhanced due diligence: the non-face-to-face menu, and the six-month PEP clock

Article 27 is the article a remote-onboarding payments firm lives in. Where the customer is not physically present or has not been met for identification purposes, and the firm has not taken the guarantees in point (2)(c) of Annex IV of the Law, specific compensating measures apply. The regulation names four:

  • establishing identity by additional identification documents, data or information;
  • measures ensuring verification or certification of the documents provided by a public authority;
  • confirmatory certification by a credit or financial institution subject to the Law or to equivalent obligations;
  • ensuring the first payment is carried out through an account opened in the customer’s name at such an institution.

On politically exposed persons, Article 30(1) requires risk-management systems that at minimum seek relevant information from the customer, refer to publicly available information, or use electronic PEP databases — and it fixes the cadence: PEP identification during the relationship must happen at least every six months. Article 30(2) then defines “senior management” for PEP approvals as meaning at least the person responsible for compliance. A firm whose PEP approvals sit below that level is non-compliant on the face of the regulation.

Worked example. An institution onboards remotely, uses a documented electronic PEP database, and re-screens its book annually at each customer’s review date. Facts to rule: annual is not six-monthly. Article 30(1) sets a floor of every six months for PEP identification during the relationship, and it is not risk-tiered — a low-risk customer does not earn a longer PEP cycle, even though ongoing due diligence under Articles 32 to 35 is risk-based. What the compliance officer does: split the cycles, leaving periodic review risk-tiered but running PEP re-identification as a fixed six-month sweep across the whole book, evidencing the sweep date. Outcome: the review calendar stays proportionate and the hard-coded clock is met independently of it.

5. Governance: the two named officers, and what internal audit owes the board

Article 40(1) requires two appointments, and conflating them is a recurring finding. First, a person responsible for compliance with the AML/CFT professional obligations at authorised management or Board level — the responsable du respect des obligations, the RR. Second, a compliance officer in charge of the control of compliance — the responsable du contrôle du respect des obligations, the RC. One sits inside the management body and owns the obligation; the other runs the control function over it.

Article 40(2) requires both names to be communicated to the CSSF, and information prior to any change in those functions — notification before, not after. Article 40(3) sets the person specification: professional experience, knowledge of the Luxembourg AML/CFT framework, and adequate hierarchy and powers. Article 41 lets the compliance officer delegate the function’s exercise without displacing responsibility; Article 43 requires that accumulating it with other functions not impede its independence.

Article 44 puts AML/CFT inside the internal audit mandate: internal audit must test and assess the risk management and control framework and the AML/CFT policies and procedures independently, and report to authorised management and the Board — or their specialised committees — with a summary report at least once a year, ensuring its recommendations are acted upon. Article 44(3) adds the group dimension: branch and majority-owned-subsidiary information under Article 4-1(1) of the Law.

6. Reporting to the FIU: two provisions worth reading closely

Article 48(1) extends the duty to inform the FIU without delay under Article 5(1)(a) of the Law to cases where the professional came into contact with a person or legal arrangement without entering into a business relationship or carrying out a transaction, where there are suspicions or reasonable grounds for suspicion. In payments terms: a declined applicant, an abandoned onboarding or a rejected counterparty can all be reportable. Read with the Article 11 duty to document all contact, it is a designed pair.

Article 48(2) is the operational half. The firm must equip itself with the means for the compliance-officer function to analyse internal reports and decide whether to communicate to the FIU, and must register itself in the tool implemented by the FIU. Its procedures must set the conditions, deadlines and steps for escalation, and the analysis and decision must be retained — including the decision not to report, the record supervisors ask for most often and firms hold least well.

Worked example. An applicant is declined on adverse-media grounds; no account is opened, no payment executed. Facts to rule: Article 48(1) applies on its terms — no business relationship is needed for the duty to arise. What the analyst does: treat the decline as an internal report under the Article 48(2) escalation procedure, run the analysis, retain it with the outcome. Outcome: either a filing, or a documented reasoned decision not to file. The indefensible third path is a decline recorded only as a commercial rejection, leaving no analysis to produce.

7. Training, in writing, including the board

Article 46(1) requires the ongoing training under Article 4(2) of the Law to cover all staff, including the management bodies and the authorised management, with specific programmes for staff in direct customer contact, staff exposed to ML/TF attempts, and staff whose duties consist directly or indirectly in AML/CFT. Article 46(2) requires a whole-personnel programme whose content and calendar are documented in writing, adapted when requirements change. The two testable elements are the board’s inclusion and the written calendar: a completion-rate dashboard is not a programme document.

8. Questions that come up

Is 12-02 still current given the EU AML package?

Yes. CSSF Regulation N° 12-02 as amended by N° 20-05 remains the applicable CSSF-level instrument. The AMLR and AMLD6 change the underlying framework on their own application dates, but do not disapply the national regulation a firm is supervised against today.

Can the RR and the RC be the same person?

They are two distinct appointments under Article 40(1) — one at authorised management or Board level, one running the control function. Article 43 requires that accumulating the compliance-officer function with others not impede its independence, effectiveness or objectivity, which is the test any combined arrangement must survive.

How often must customer information be updated?

Articles 32 to 35 govern ongoing due diligence, including verifying and where appropriate updating information within maximum timeframes. The cadence is risk-based — unlike the fixed six-month PEP identification cycle in Article 30(1).

Is the annual questionnaire the same thing as the risk assessment?

No. The assessment is the Article 4(1) exercise; the questionnaire is the return through which the CSSF collects it — which is why it must be maintained as data, not a document.

9. What to do, today

  • Build the control matrix from 12-02 article numbers, not the Law — that is the granularity findings are written at.
  • Check the Article 4(1) source list is genuinely incorporated, each source traceable into the methodology.
  • Separate the PEP re-identification sweep from the risk-tiered review cycle and run it every six months across the whole book, with approvals at or above the person responsible for compliance.
  • Verify the RR and RC names on file with the CSSF are current, and that the process notifies before a change.
  • Ask internal audit for the last annual AML/CFT summary report to the Board. If it does not exist, that is an Article 44(2) gap.
  • Test the Article 48(1) path on a declined applicant: can you produce the analysis and the reasoned decision not to report?
  • Check the Article 14(2) linked-operations detection actually aggregates to the €15,000 trigger.

Related: Filing an STR with the Luxembourg CRF · The CSSF AML/CFT data collection · Remote identification in Luxembourg · CSSF 26-906 internal governance

Related reads.