Klavius

CSSF Circular 18/698: what it asks of the second line

Three white walls in a row, the indigo Klavius ribbon passing through an arch in the middle one
In brief

Circular CSSF 18/698 is the CSSF's rulebook for how a Luxembourg fund manager is organised. For the second line it asks for four things: independent control functions with direct access to the board and the CSSF, a compliance function with a charter and a risk-based monitoring plan, a yearly summary report sent to the CSSF within five months of year end, and Management Information discussed every month. Each one leaves a document the CSSF can ask to see.

Circular CSSF 18/698 of 23 August 2018 is the CSSF's rulebook for how a Luxembourg investment fund manager (IFM) is authorised and organised. It replaced Circular 12/546 and took over the compliance and internal audit rules of Circulars 04/155 and IML 98/143 (CSSF 18/698, cover letter). Most summaries walk through it chapter by chapter. This guide reads it from the desk of the second line: the compliance officer, the risk manager and the conducting officers they report to. Four blocks matter to that desk, and each one produces documents the CSSF can ask to see.

Who it applies to

The circular applies to Luxembourg ManCos under Chapter 15 of the 2010 Law, management companies under Articles 125-1 and 125-2 of Chapter 16, Luxembourg branches of IFMs under Chapter 17, self-managed investment companies (SIAGs), authorised AIFMs under the 2013 Law and internally managed AIFs (FIAAGs). It does not apply to IFMs under Chapter 18 of the 2010 Law, nor to the entities of Article 3 of the 2013 Law that fall outside that definition (CSSF 18/698, cover letter).

One practical note: the English version is a translation. "In case of discrepancies between the French and the English text, the French text shall prevail" (CSSF 18/698, page 1).

Where the second line sits

The circular requires internal governance built on three lines of defence. The second line is made of the permanent risk management and compliance functions, together with support functions such as IT and accounting. Internal audit is the third line (points 154 to 157).

Each internal control function has its own head, appointed under a written procedure, approved by the board (the circular's "management body/governing body") and notified to the CSSF in writing (point 164). The heads must be able to contact the board, the approved statutory auditor and the CSSF directly and on their own initiative (points 165 and 171). Independence is broken if control staff check tasks they perform themselves, sit inside the business units they control, or are paid on the performance of what they control (point 172). The work must be documented so that interventions and conclusions can be traced (point 183), and the heads must verify that their recommendations are followed up and report on it (point 185).

Two combinations are ruled out. Compliance and internal audit cannot be performed by the same person (point 169), and the risk manager cannot also run internal audit. Combining compliance and risk management is permitted (point 201).

The conducting officers above it

An IFM needs at least two conducting officers, in principle permanently located in Luxembourg (points 78 and 79). They sit on an executive committee that meets at least monthly in Luxembourg, with written minutes (points 90, 100 and 101). Each conducting officer is assigned specific areas, which include compliance, risk management, internal audit and AML/CFT (point 94). The same conducting officer cannot both take risks and control them: risk management and investment management cannot sit with one person (point 96).

The circular also sets a floor for substance: at least three full-time people at the Luxembourg head office performing key functions (point 123).

The compliance function

This is the core of the circular for a compliance officer. The IFM must have its own compliance function in Luxembourg (point 226). Its aim is "to anticipate, identify and assess the compliance risks of an IFM as well as to assist the senior management in controlling these risks", on an ongoing basis and without delay (point 227).

  • A charter. Objectives, responsibilities and powers are set in a compliance charter drawn up by the function and approved by senior management and ultimately by the board (points 229 to 232).
  • A record of the rules. The function identifies the standards the IFM is subject to and keeps a record of the main rules, accessible to the relevant staff (point 233).
  • A risk-based plan. It identifies the compliance risks and assesses their significance. That classification must allow it "to establish its control plan according to the risk" (point 233). This is where the compliance risk assessment and the compliance monitoring plan come from.
  • New business first. Compliance risk is assessed before the IFM enters new activities, products or business relationships (point 233).
  • Regular testing. The function verifies compliance with the policy and procedures on a regular basis, and the Compliance Officer assesses and controls compliance risk regularly (point 235).
  • One place for problems. All compliance problems identified in the IFM are centralised in the function (point 236).
  • Training. An ongoing training programme for staff (point 239).

The Compliance Officer is notified to the CSSF beforehand and is in principle employed full time (points 240 and 241). A part-time Compliance Officer needs prior CSSF approval (point 243). An IFM limited to managing UCIs can delegate the performance of the function by derogation, but it must still name a Compliance Officer among its employees to monitor the external expert (points 248 and 254).

What the function reports, and when

The Compliance Officer reports in writing to senior management on a regular basis, and to the board where appropriate. Each report states the risks, their seriousness and the corrective measures proposed (point 256). At least once a year, a summary report is approved by the board and sent to the CSSF within five months of the financial year end (points 257 and 258).

The CSSF recommends that the summary report cover the organisation of the function, the work done during the year including regulatory monitoring, and "the compliance monitoring plan adopted using a risk-based approach", with the activities monitored, the risk assessed for each and the timetable "following a multi-year programme". It also lists open recommendations and shortcomings, in particular on AML/CFT and the monitoring of delegates (point 259). Point 260 adds areas to consider, from NAV errors and investment breaches to complaints, whistleblowing and interactions with the supervisor.

Management Information ties it together. Every IFM draws up Management Information that monitors its own activity and its delegates, including the result of the compliance function's work (points 341 and 342). Its analysis is presented and discussed at the monthly executive committee in Luxembourg, and the decisions are minuted (point 345).

Delegation, briefly

An IFM may delegate functions, but the monitoring of delegated activities can never be delegated (points 417 and 451). Every delegate needs a prior written initial due diligence (point 441), periodic due diligence follows a multi-year plan, generally three years (point 449), and the CSSF is notified beforehand when portfolio management, risk management, UCI administration or valuation is delegated (point 424). We covered what the CSSF found on this in 2025 in a separate post on delegate oversight.

What the CSSF can ask to see

DocumentPointsOwner or approvalWhen
Compliance charter229 to 232Senior management, then the boardUpdated when the rules change
Compliance monitoring plan, risk-based233, 259Described in the summary reportMulti-year programme
Compliance summary report257 to 259The boardYearly, to the CSSF within five months of year end
Risk management report212Drawn up by the risk management functionYearly, to the CSSF within five months of year end
Internal audit summary report298 to 301The boardYearly, to the CSSF within five months of year end
Management Information341 to 345Executive committeeDiscussed at least monthly, decisions minuted
List of delegates425The IFMYearly, to the CSSF within five months of year end
Periodic due-diligence plan449The IFMMulti-year, generally three years

Where Klavius fits

Klavius covers the compliance and delegation rows of that table. Regulatory Watch reads CSSF, ESMA and European Commission publications and proposes new controls for an officer to validate. From the policies and controls the compliance officer supplies, Klavius drafts the compliance risk assessment and the monitoring plan with every recommendation sourced, then keeps the actions, owners and management reporting on the same record. Delegate Oversight runs the due-diligence questionnaires, the reminders and the escalations. Klavius reads and proposes; the officers validate and sign. The Compliance page shows how the CRA and CMP are built, and the Delegate Oversight page covers delegates.

Sources

  • CSSF, Circular CSSF 18/698 on the authorisation and organisation of investment fund managers incorporated under Luxembourg law, 23 August 2018, English version (the French text prevails), points 74 to 101, 123, 154 to 185, 201, 212, 226 to 260, 298 to 301, 341 to 345, 417 to 451. Publication page.
← All posts