Circular CSSF 18/698 runs to 96 pages in English and 621 numbered points. These are the questions it answers most often for the people who have to apply it, each with the point to check in the text. Every answer comes from the circular itself (CSSF 18/698). For the compliance function read as a whole, see our guide to what 18/698 asks of the second line.
1. What is CSSF Circular 18/698?
It is the CSSF circular of 23 August 2018 on the authorisation and organisation of investment fund managers incorporated under Luxembourg law, with specific provisions on the fight against money laundering and terrorist financing. It replaced Circular 12/546 and ended the application of Circulars 04/155 and IML 98/143 to IFMs. The French text prevails over the English translation in case of discrepancy (cover letter and page 1).
2. Who does it apply to?
Luxembourg ManCos under Chapter 15 of the 2010 Law, management companies under Articles 125-1 and 125-2 of Chapter 16, Luxembourg branches of IFMs under Chapter 17, self-managed investment companies (SIAGs), AIFMs authorised under Chapter 2 of the 2013 Law and internally managed AIFs (FIAAGs). IFMs under Chapter 18 of the 2010 Law are out of scope (cover letter).
3. How many board members and conducting officers are required?
At least three members of the board (the circular's "management body/governing body", point 59) and at least two conducting officers (point 78). Conducting officers must in principle be permanently located in Luxembourg, and at least two must be employees of the IFM working full time on its business (points 79 and 80). Below EUR 1.5 billion of assets under management, a conducting officer can hold at most two conducting-officer mandates in IFMs; above it, the two legally required conducting officers cannot hold any other (points 81 and 82).
4. How many staff must an IFM have in Luxembourg?
At least three full-time people at the Luxembourg head office performing key functions, more as the business grows in size and complexity (point 123). Delegation on a scale that leaves the IFM a letter-box entity breaches the conditions of its authorisation (points 413 and 414).
5. How often must the board and the executive committee meet?
The board meets at least once a quarter, with an agenda and written minutes (points 74 and 75). The conducting officers form an executive committee that meets in Luxembourg at least monthly, also with written minutes (points 90, 100 and 101). The analysis of the Management Information is presented and discussed at those monthly meetings (point 345).
6. What does the compliance function have to do?
Anticipate, identify and assess the IFM's compliance risks and help senior management control them, continuously (point 227). In practice: a compliance charter approved by the board (points 229 to 232), a record of the applicable rules, a classification of compliance risks that drives a risk-based control plan, an assessment before any new activity or product (point 233), regular testing (point 235), a central log of compliance problems (point 236) and staff training (point 239).
7. Can the compliance function be outsourced?
Only by derogation. An IFM whose licence is limited to managing UCIs can ask the CSSF, with a justified prior request, to delegate the performance of the function to an external expert (points 248 and 253). An IFM that also provides the additional services of Article 101(3) of the 2010 Law or Article 5(4) of the 2013 Law, such as discretionary management, cannot in principle (point 249). In every case the IFM keeps a Compliance Officer among its own employees to monitor the expert, notified to the CSSF beforehand (point 254).
8. Can one person combine compliance with risk management or internal audit?
Compliance and risk management can be combined (point 201). Compliance and internal audit cannot be held by the same person (point 169), and neither can risk management and internal audit (point 201). The conducting officer in charge of internal audit cannot also be the Compliance Officer, the AML/CFT Compliance Officer or the risk manager (point 97).
9. What must be sent to the CSSF every year?
Within five months of the financial year end:
- the compliance function's summary report (point 258);
- the risk management function's report on the adequacy and effectiveness of risk management (point 212);
- the internal audit function's summary report (point 301);
- the list of all delegates (point 425);
- the updated table of mandates held by board members and conducting officers (point 107);
- for ManCos under Chapter 15 and AIFMs under Chapter 2 of the 2013 Law, an update of the risk management procedure (point 217).
10. What goes into the compliance summary report?
The CSSF recommends at least: the organisation of the function and its resources, the work done during the year including regulatory monitoring, the risk-based compliance monitoring plan with the activities monitored, the risk assessed for each and a multi-year timetable, and the main recommendations and open shortcomings, in particular on AML/CFT and delegate monitoring (point 259). Point 260 lists further areas to consider, such as NAV errors, breaches of investment restrictions, complaints and whistleblowing. The report is approved by the board (point 257).
11. Can an IFM delegate portfolio management, and what must it keep?
Yes, within limits. The CSSF is notified beforehand when portfolio management, risk management, UCI administration or valuation is delegated (point 424), and every delegate needs a prior written initial due diligence (point 441). Some tasks stay with the IFM, including the choice of delegates and "the monitoring and control of delegated functions" (point 417). Under no circumstances can the monitoring of delegated activities itself be delegated (point 451). Our post on what the CSSF found on delegate oversight in 2025 covers the detail.
12. Does 18/698 cover AML/CFT?
Yes, in sub-chapter 5.4. Every IFM is subject to the AML/CFT Law, CSSF Regulation 12-02 and the CSSF's AML/CFT circulars (point 305). It must designate an AML/CFT Compliance Officer at senior management level and an AML/CFT Compliance Officer, both permanently located in Luxembourg and notified to the CSSF (points 313 to 315).
Where Klavius fits
Most of these answers end in a document: a charter, a monitoring plan, a report, a due-diligence file. Klavius keeps the compliance and delegation ones on one record. It drafts the compliance risk assessment and the monitoring plan from the documents the compliance officer supplies, with every recommendation sourced, and runs the due-diligence questionnaires, reminders and escalations for delegates. The officers validate and sign. See the Compliance page and the Delegate Oversight page.
Sources
- CSSF, Circular CSSF 18/698 on the authorisation and organisation of investment fund managers incorporated under Luxembourg law, 23 August 2018, English version (the French text prevails). Publication page.
