Klavius

CSSF 18/698 delegate oversight: what the CSSF's 2025 Annual Report expects from Luxembourg fund managers

An indigo tile with an eye icon above the Klavius ribbon
In brief

The CSSF's Annual Report 2025, published on 4 September 2026, puts delegate oversight at the top of its findings: 18% of on-site observations at IFMs, 56% of sanctions since 2020, and a 2026 study against ESMA's third-party principles and Circular 18/698. The findings describe qualitative questionnaires without thresholds, missing evidence and boards that never see the results. Each maps onto a point of the circular, and the fix is a record kept current between reviews.

The CSSF published its Annual Report 2025 on 4 September 2026. For the second line of defence at an investment fund manager, the pages that matter are 79 to 82 of chapter XI. They say three things. Supervision of delegated activities was the largest category of observations from on-site inspections at IFMs in 2025, at 18%. Of the administrative sanctions imposed on IFMs between 2020 and 2025, 56% concerned a lack of supervision of delegated activities. And the CSSF confirms that in 2026 it is running a study on a sample of IFMs to assess their compliance with ESMA's third-party risk principles and with the delegation rules of Circular CSSF 18/698 (CSSF Annual Report 2025, pages 68 and 79 to 82). This post sets out what the report found, what the circular requires, and what to check before the study reaches your desk.

What the 2025 report found

The on-site inspections at IFMs in 2025 covered entities managing about 46% of the assets under management at Luxembourg IFMs, 24 of them with more than EUR 10 billion. Grouped by theme, supervision of delegated activities came first at 18% of the observations, ahead of collective portfolio management and support functions at 16% each (CSSF Annual Report 2025, page 79).

The most detailed findings concern best execution at eight inspected IFMs, and they read as a description of weak delegate oversight rather than of best execution itself. The CSSF noted that due diligence on delegates "generally lacked a thorough assessment of their controls". Ongoing monitoring relied on periodic questionnaires that "elicit qualitative responses from delegates, without including quantitative data", with no quantified metrics, no defined thresholds and no independent verification. Some periodic reports did not let the IFM isolate the funds it manages, identify the performance of all brokers or explain cases where tolerance thresholds were exceeded. Some IFMs had no documented evidence of the controls carried out on their delegates. And some never discussed the results at the executive committee or the board, whose meeting packs "generally did not include reports on this subject" (CSSF Annual Report 2025, page 80).

The sanctions analysis puts a number on the pattern.

Between 2020 and 2025, 56% of the administrative sanctions imposed on IFMs concerned a lack of supervision of delegated activities, 47% concerned governance and internal control, and 31% concerned the portfolio management function, in particular the due diligence obligation and the supervision of best execution. CSSF Annual Report 2025, page 82.

The categories overlap, which is the point: a delegation failure is usually recorded as a governance failure too (CSSF Annual Report 2025, page 82).

The 2026 study: ESMA's principles meet Circular 18/698

The study was announced in the CSSF's 2026 supervisory priorities for the investment fund sector on 31 March 2026: the CSSF "will launch in 2026 a study among a sample of IFMs to assess their compliance" with ESMA's principles on third-party risk supervision and "those related to delegation outlined in Circular CSSF 18/698", covering the integration of a third-party risk framework into the overall risk management process (CSSF, 31 March 2026). The same document announces a common supervisory action on the risk management function in the second half of 2026, so delegates will be looked at from two directions.

ESMA's fourteen principles, published on 12 June 2025, are non-binding and addressed to supervisors: they describe what national authorities are expected to check at the entities they supervise (ESMA, 12 June 2025). Three of them describe the test an IFM will face. Principle 8 expects contracts with "clearly defined service level, performance indicators and reporting processes". Principle 9 expects ongoing monitoring whose reports are "reviewed by its governing bodies" and which "includes periodic on-site visits". Principle 3 expects board members to "seek and receive regular and relevant management information" on third-party risk (ESMA principles, points 23, 31, 35 and 36). None of it is new to a Luxembourg IFM. It restates, in EU supervisory language, what the CSSF wrote in 2018.

What Circular 18/698 requires

Sub-chapter 6.2 of Circular CSSF 18/698 is the operating manual for delegation. The points below are the ones the 2025 findings map onto (Circular CSSF 18/698, points 441 to 476).

  • Due diligence without a thorough assessment of the delegate's controls. Point 460 lists the initial due-diligence criteria, including the delegate's control functions and its ability to provide sufficient reports and key performance indicators. Point 462 requires a written, critical report, signed before the contract enters into force (point 463).
  • Questionnaires without quantitative data, thresholds or verification. Point 474: conducting officers receive regular detailed reports "including in particular key performance indicators", and the IFM "must determine and implement its own key performance indicators when the key performance indicators provided by the delegate are not sufficient".
  • No method to read the reports, threshold breaches unexplained. Point 475: a documented methodology to analyse the results, and the IFM's "own warning systems", with the analysis available to the CSSF on request.
  • No documented evidence of the controls carried out. Points 464, 465 and 470: initial and periodic due-diligence assessments are documented, kept at the head office and sent to the CSSF "without delay" on request.
  • Results that never reach the executive committee or the board. Point 473: the Management Information system must allow the monitoring of the delegates' activity. Point 469: each periodic report follows up the previous observations with action plans, a timetable and the escalation measures taken.

Two structural rules sit above the list. Point 449 requires a multi-year plan, generally three years, for periodic due diligence on every delegate, updated on a risk basis. Point 451 states that under no circumstances can the monitoring of delegated activities itself be delegated, and that the IFM needs qualified staff in Luxembourg, named in the procedure.

A short checklist before the study

  1. The multi-year plan is current. Every delegate has a risk tier, a due-diligence frequency that follows from it and a date for the next review (point 449).
  2. Questionnaires carry numbers. Quantitative KPIs against defined thresholds, with the IFM's own KPIs where the delegate's are not enough (point 474).
  3. The reading method is written down. A documented methodology and warning thresholds turn a report into a conclusion, and the analysis is on file (point 475).
  4. Findings have owners and dates. The previous review's observations, the action plan and the timetable appear in the next report (point 469).
  5. The board sees it. Delegate oversight is a standing item in the executive committee and board packs (point 473 and ESMA principle 3).
  6. Everything can be produced on request. Due-diligence reports, evidence of controls and the written analysis can go to the CSSF without delay (point 465).

Where Klavius fits

Klavius Delegate Oversight keeps that record in one place. It runs the due-diligence questionnaire workflow per delegate and risk tier, sends the scheduled reminders, and escalates incidents to the management line when a period closes with a breach. Findings carry their owner, action plan and date from one review to the next, and the board pack draws on the same record the officers work in. Klavius reads the delegate's returns and proposes; the officer assesses and signs. A delegate that is also an ICT provider is one record, shared with the DORA register. If the 2025 findings describe your questionnaires, the Delegate Oversight page shows how the workflow is built.

Sources

← All posts