Remote onboarding in Luxembourg — compensating measures
Luxembourg’s rule is short, conditional, and turns on a phrase most summaries skip: “or has not been met by or on behalf of the professional”. Article 27 of CSSF Regulation No 12-02, as amended by CSSF Regulation No 20-05, requires specific compensating measures where the customer is not physically present or has not been met by or on behalf of the professional for identification purposes — and where the professional has not taken the guarantees indicated in point (2)(c) of Annex IV to the Law of 12 November 2004.
1. The trigger has two limbs and a carve-out
| Element | What it means |
|---|---|
| Not physically present | The obvious case: a digital onboarding with no meeting |
| Or has not been met by or on behalf of the professional | The broader case: a meeting that did not happen for identification purposes, or happened with someone other than the professional or its representative |
| Unless the Annex IV(2)(c) guarantees were taken | A conditional carve-out — the compensating measures are required only where those guarantees are absent |
Where the trigger is met, the professional must apply specific measures to compensate the potentially higher risk that this type of relationship presents. The Regulation frames these as risk-compensation rather than as a procedure to be followed — which is the structural difference from the Spanish and Italian models.
2. The safeguards that switch the trigger off
Annex IV to the Law lists the higher-risk factors that Article 3-2(1) obliges professionals to consider. Point (2)(c) covers non-face-to-face relationships without certain safeguards, and names them: electronic identification means, relevant trust services under Regulation (EU) No 910/2014 (eIDAS), or another secure remote identification process regulated, recognised, approved or accepted by the relevant national authorities.
In Circular CSSF 20/740 the CSSF stated that verification via live video-chat, or electronic identification means, could be considered an appropriate safeguard, and pointed to its FAQ on video identification. That FAQ is narrow:
- video identification is a real-time video conference run by a specifically trained employee of the professional or its provider;
- a robot-only flow, or a customer uploading documents or a video, does not qualify and needs supplementary safeguards for its automated character;
- it is unavailable where there is suspicion, doubt about prior data, or a higher-risk circumstance;
- only official documents with optical security features are accepted; the employee checks hologram, machine-readable zone and photograph against data the customer entered beforehand.
So an attended session meeting the FAQ, or a notified eID, can take a relationship outside Article 27; a selfie-and-document app generally cannot on its own. On wallets, see eIDAS 2 digital identity wallet acceptance.
3. The four compensating measures
The Regulation says the measures “may notably be” the following, so the list is indicative rather than exhaustive:
- measures ensuring that the customer’s identity is established by additional identification documents, data or information;
- additional measures ensuring the verification or certification of the provided documents by a public authority;
- confirmatory certification by a credit institution or a financial institution subject to the Law, or subject to equivalent professional obligations on AML/CFT;
- measures ensuring that the first payment of the transactions is carried out via an account opened in the customer’s name with a credit or financial institution subject to the Law or to equivalent professional obligations.
Because the list is indicative and the obligation is to compensate the risk, the number of measures is not fixed the way it is in France. What the Regulation asks is that the measures actually address the elevated risk the remote channel creates — which puts the weight on the firm’s own risk analysis rather than on a count. The EBA guidelines add similar options: a single-use, time-limited passcode, biometric comparison against independent sources, telephone contact, or mailing to the customer.
4. What that means for design
Three consequences follow from an open-ended, risk-compensating standard:
- The risk analysis becomes the primary artefact. Where a rule requires compensation of a risk, the evidence is the analysis identifying the risk and explaining why the chosen measures address it. Article 4(2) of the Regulation adds that risks from new delivery mechanisms and technologies are assessed before launch.
- The EBA guidelines fill the gap. Because the national text is not prescriptive on technique, the EBA guidelines on remote customer onboarding are the reference for what good looks like.
- Consistency across the group matters more. An entity in a group operating under prescriptive rules elsewhere will be asked why its controls are lighter. The defensible answer is a documented risk analysis, not the absence of a rule.
5. The pre-implementation assessment
The EBA Guidelines on the use of remote customer onboarding solutions (EBA/GL/2022/15), which the CSSF publishes on its website, apply from 2 October 2023. Their core requirement is an assessment before go-live, defined in the firm’s own procedures:
| Element (EBA GL para. 14) | What the file should show |
|---|---|
| Data adequacy | Completeness and accuracy of data and documents collected; reliability and independence of the sources used |
| Business-wide impact | Effect on ML/TF, operational, reputational and legal risks |
| Mitigation | A mitigating measure or remedial action for each risk identified |
| Fraud and ICT testing | Tests of impersonation fraud and other ICT and security risks |
| End-to-end testing | Testing on the customers, products and services actually in scope |
An eID scheme notified under Article 9 of eIDAS at assurance level “substantial” or “high”, or relevant qualified trust services, is treated as meeting the data, fraud and end-to-end criteria. The firm must be able to show the CSSF which assessments it ran, their outcome and why the solution fits the customers, geographies and products in scope. The management body approves the policies; the AML/CFT compliance officer ensures they are applied and reviewed.
After launch, the policy defines review frequency and ad hoc triggers: changed risk exposure, deficiencies found by monitoring, audit or supervision, rising fraud attempts, legal change. When a flaw surfaces, affected relationships are reviewed highest-risk first.
6. Three worked cases
Case A — app onboarding of a resident retail customer. Facts: an e-money institution onboards Luxembourg residents through an unattended document-and-selfie check, with no other measure. Rule: the customer was not met, and an automated check is not video identification under the FAQ, so Article 27 engages. What the compliance officer does: confirms the EBA unattended controls — image captured at the time of verification, liveness detection, strong matching algorithms, document checks against official databases such as the Council’s PRADO register — then adds an Article 27 measure bringing in an independent source, usually the first payment. Outcome: the risk analysis records why that pairing addresses residual impersonation risk.
Case B — a director onboarding from a third country. Facts: a Luxembourg company applies for a payment account; its sole director completes the flow from outside the EEA. Rule: the FAQ allows a legal person’s representative to be video-identified, but not in higher-risk circumstances; Annex IV lists residence in higher-risk areas as a risk factor, which can trigger Article 3-2 enhanced due diligence. What the compliance officer does: checks the entity category is eligible remotely; collects the registry extract, the director’s authority and beneficial-ownership data; applies EBA controls against spoofed IP addresses and VPNs; and, for a higher-risk country, adds Article 26 measures such as management approval. Outcome: onboarding with a documented EDD rationale, or a decline.
Case C — relying on the first payment. Facts: a firm uses an incoming transfer from an EU bank account as its compensating measure. Rule: Article 27 accepts a first payment via an account in the customer’s name at an institution subject to the Law or equivalent obligations. What the compliance officer does: automates a strict payer-name match, keeps the account restricted until it clears, and rejects third-party payers — payment from unassociated third parties is itself an Annex IV factor. Outcome: a clean match closes the loop; a mismatch stops onboarding and is assessed for suspicion. Article 26a lets such a payment be presumed to satisfy identity verification only in a justified low-risk case.
Article 28 of Regulation 12-02 requires analyses and decisions to be documented in writing and available to the competent authorities — the documentation standard the CSSF applies more generally.
7. Records, outsourcing and the provider
Article 3(6) of the Law keeps CDD records — expressly including data from electronic identification means — for five years after the relationship ends. For video identification the FAQ requires at least screenshots and the audio of the entire conversation; the EBA guidelines add time-stamping and readability for ex-post checks.
- Responsibility stays with the professional, even when the process or an automated tool is outsourced; the firm must be able to intervene when the provider changes it.
- Provider storage is transitional: only as long as needed to transmit data, encrypted, least-privilege access.
- No certification: the CSSF assesses tools as integrated into each firm’s framework.
- Data protection: the FAQ recommends clearing the process with the CNPD.
Where identification cannot be completed, the professional must not enter into the relationship. Compare remote identification in Belgium.
8. FAQ
How many compensating measures are required?
The Regulation does not fix a number. It requires specific measures to compensate the potentially higher risk, and lists four that “may notably” be used — so the adequacy of the combination is judged against the firm’s risk analysis.
Does a video call count as being “met”?
The CSSF treats a live video-chat run by a trained employee, meeting its FAQ conditions, as a possible safeguard for the lack of face-to-face contact. A recorded video or a robot-only flow does not qualify and needs supplementary safeguards.
Is a selfie-and-ID app enough on its own?
Generally not. It falls outside the FAQ definition of video identification, so Article 27 measures apply unless a notified eID or qualified trust service is used.
Does a notified eID remove the need for compensating measures?
Electronic identification means are an Annex IV(2)(c) safeguard. The firm should still assess residual risks such as lost or revoked credentials, as the EBA guidelines ask.
Has the CSSF adopted the EBA remote onboarding guidelines by circular?
The CSSF publishes them on its website; we have not identified a dedicated adoption circular. They apply from 2 October 2023.
Can the directors of a corporate customer be identified remotely?
Yes. The FAQ covers a legal person’s representative, proxy-holders and beneficial owners, subject to the higher-risk exclusion.
How long must video recordings be kept?
Screenshots and the full audio are CDD records, kept for five years after the relationship ends or the occasional transaction.
9. What to do, today
- Map each onboarding flow against the two limbs of Article 27 and record whether an Annex IV(2)(c) safeguard applies.
- Where Article 27 applies, name the compensating measure in the AML policy and say why it fits.
- Rebuild the pre-implementation file to the five EBA elements and keep the test evidence.
- Set review frequency and ad hoc triggers; log remediation.
- Check retention: time-stamped records, full session audio, five years.
- Recheck provider change-notification clauses.
Related: Remote onboarding compared across the EU · CSSF Regulation 12-02 — the Luxembourg AML rulebook · EBA remote onboarding guidelines · RCS — the Luxembourg company register


