{"id":"circulars/cssf-18-680","title":"Circular CSSF 18/680","type":"circular","date":"2018-01-23","kind":"circular","html":"<p>Circular CSSF 18/680 is a CSSF circular, published 23 January 2018 and updated 8 April 2025. Subject: Joint Guidelines of the three European Supervisory Authorities on the measures payment service providers should take to detect missing or incomplete information on the payer or the payee. It was repealed by <a href=\"/lhoft?page=circulars%2Fcssf-25-879\" class=\"wikiLink\" data-target=\"circulars/cssf-25-879\">Circular CSSF 25/879</a>.</p>\n<p>Relevant for: AISPs, Credit institutions, E-money institutions, Payment institutions, Payment institutions/electronic money institutions/AISPs, Virtual asset service providers (VASPs).</p>\n<p>Main topic: Financial crime. Keywords: AML/CFT, Payment Service Provider (PSP).</p>\n<h2>Text</h2>\n<p>In case of discrepancies between the French and the English text, the French text shall prevail.</p>\n<p>Luxembourg, 23 January 2018</p>\n<p>To all payment service providers and all intermediary payment service providers</p>\n<p>Re: European Supervisory Authorities’ Joint Guidelines on the measures payment service providers should take to detect missing or incomplete information on the payer or the payee</p>\n<p>Ladies and Gentlemen, The purpose of this circular is to draw your attention on the Joint Guidelines of the European Supervisory Authorities (ESMA/EBA/EIOPA) (hereafter, the “European Supervisory Authorities”) 1 under Article 25 of Regulation (EU) 2015/847 2 on the measures payment service providers should take to detect missing or incomplete information on the payer or the payee, and the procedures they should put in place to manage a transfer of funds lacking the required information (the “Guidelines”) and with which the CSSF intends to comply. The Guidelines set out the opinion of the European Supervisory Authorities in this respect and notably apply to: (a) payment service providers (PSPs) as defined in Article 3(5) of Regulation (EU) 2015/847 where they act as the PSP of the payee, and</p>\n<p>The Guidelines are annexed to this circular. They are also available at: <a href=\"https://esas-jointcommittee.europa.eu/Publications/Guidelines/Joint%20Guidelines%20to%20prevent%20terrorist%20financing\" target=\"_blank\" rel=\"noreferrer\">https://esas-jointcommittee.europa.eu/Publications/Guidelines/Joint%20Guidelines%20to%20prevent%20terrorist%20financing</a> %20and%20money%20laundering%20in%20electronic%20fund%20transfers%20(JC-GL-2017-16).pdf 2 Regulation (EU) 2015/847 of the European Parliament and of the Council of 20 May 2015 on information accompanying transfers of funds and repealing Regulation (EC) No 1781/2006 (Text with EEA relevance): <a href=\"http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32015R0847\" target=\"_blank\" rel=\"noreferrer\">http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32015R0847</a></p>\n<p>(b) intermediary payment service providers (IPSPs) as defined in Article 3(6) of Regulation (EU) 2015/847. The PSPs and IPSPs referred to in points (a) and (b) above are thus requested to refer to the Guidelines for information on: -</p>\n<p>the factors PSPs and IPSPs should consider when establishing and implementing procedures to detect and manage transfers of funds that lack required information on the payer and/or the payee and the measures they should take to manage the risk of money laundering or terrorist financing (“ML/TF”) where the required information on the payer and/or the payee is missing or incomplete.</p>\n<p>In order to detect and manage these transfers of funds with missing or incomplete information, PSPs and IPSPs shall notably establish, and maintain through regular review, effective policies and procedures, that are proportionate to the nature, size and complexity of their business. These policies and procedures shall also be proportionate to the ML/TF risks to which the PSPs and PSPIs are exposed. Thus, they shall, for instance, set out clearly which transfers of funds have to be monitored in real time and which transfers of funds can be monitored on an ex-post basis. Furthermore, PSPs and IPSPs shall take into account the “Guidelines of the European Supervisory Authorities on risk factors” 3 that the CSSF brought to the attention of the supervised undertakings and entities by way of Circular CSSF 17/661 of 24 July 2017, in particular where a country associated with high ML/TF risk has been identified. Other requirements set down in these Guidelines and with which the PSPs and IPSPs should comply, are the documentation and record-keeping of all the follow-up actions, including the reasons behind the decisions taken, so that the PSPs and IPSPs are later capable of responding to possible requests by the competent authorities. The Guidelines shall apply six months from their date of issue, which was on 16 January 2018. The CSSF adopts the Guidelines by way of this circular.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-18-680/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf18_680eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}