Remote onboarding in Luxembourg — compensating measures
Luxembourg’s rule is short, conditional, and turns on a phrase most summaries skip: “or has not been met by or on behalf of the professional”. Article 27 of CSSF Regulation No 12-02, as amended by CSSF Regulation No 20-05, requires specific compensating measures where the customer is not physically present or has not been met by or on behalf of the professional for identification purposes — and where the professional has not taken the guarantees indicated in point (2)(c) of Annex IV to the Law.
1. The trigger has two limbs and a carve-out
| Element | What it means |
|---|---|
| Not physically present | The obvious case: a digital onboarding with no meeting |
| Or has not been met by or on behalf of the professional | The broader case: a meeting that did not happen for identification purposes, or happened with someone other than the professional or its representative |
| Unless the Annex IV(2)(c) guarantees were taken | A conditional carve-out — the compensating measures are required only where those guarantees are absent |
Where the trigger is met, the professional must apply specific measures to compensate the potentially higher risk that this type of relationship presents. The Regulation frames these as risk-compensation rather than as a procedure to be followed — which is the structural difference from the Spanish and Italian models.
2. The four measures
The Regulation says the measures “may notably be” the following, so the list is indicative rather than exhaustive:
- measures ensuring that the customer’s identity is established by additional identification documents, data or information;
- additional measures ensuring the verification or certification of the provided documents by a public authority;
- confirmatory certification by a credit institution or a financial institution subject to the Law, or subject to equivalent professional obligations on AML/CFT;
- measures ensuring that the first payment of the transactions is carried out via an account opened in the customer’s name with a credit or financial institution subject to the Law or to equivalent professional obligations.
Because the list is indicative and the obligation is to compensate the risk, the number of measures is not fixed the way it is in France. What the Regulation asks is that the measures actually address the elevated risk the remote channel creates — which puts the weight on the firm’s own risk analysis rather than on a count.
3. What that means for design
Three consequences follow from an open-ended, risk-compensating standard:
- The risk analysis becomes the primary artefact. Where a rule prescribes a procedure, the evidence is conformity. Where it requires compensation of a risk, the evidence is the analysis identifying the risk and explaining why the chosen measures address it.
- The EBA guidelines fill the gap. Because the national text does not prescribe a technical procedure, the European Banking Authority’s guidelines on remote customer onboarding solutions are the natural reference for what good looks like, and a Luxembourg firm should be able to show it has taken them into account.
- Consistency across the group matters more. A Luxembourg entity in a group operating under prescriptive national rules elsewhere will face the question of why its own controls are lighter. The defensible answer is a documented risk analysis, not the absence of a rule.
4. A worked case
Facts: an e-money institution onboards Luxembourg customers digitally using an automated document-and-selfie check, with no meeting at any point and no additional measure.
What the rule says: the customer is not physically present and has not been met by or on behalf of the professional, so Article 27 engages unless the Annex IV(2)(c) guarantees have been taken. Specific compensating measures are then required, and an automated identity check is the baseline being compensated for rather than the compensation itself.
What the practitioner does: adds a measure from the indicative list that introduces an independent source — the first-payment route is usually the most practical, because it produces evidence from a regulated institution and can be verified from the firm’s own transaction records. The risk analysis then records why that measure addresses the specific residual risk, and the AML policy names it.
Article 27 sits alongside the rest of Regulation 12-02, and the neighbouring provisions are worth reading in the same pass — Article 28 on cross-border correspondent relationships requires the analysis and resulting decision to be documented in writing and available to the competent authorities, which is the documentation standard the CSSF applies more generally.
FAQ
How many compensating measures are required?
The Regulation does not fix a number. It requires specific measures to compensate the potentially higher risk, and lists four that “may notably” be used — so the adequacy of the combination is judged against the firm’s risk analysis.
Does a video call count as being “met”?
The article distinguishes the customer not being physically present from not having been met by or on behalf of the professional for identification purposes. Firms relying on a remote meeting should record how they have analysed that distinction.
Where should we look for technical expectations?
Since the national text is not prescriptive on technique, the EBA guidelines on remote customer onboarding solutions are the natural reference, and a firm should be able to show it has taken them into account.
Related: Remote onboarding compared across the EU · CSSF internal governance · EBA remote onboarding guidelines


