{"id":"circulars/cssf-26-906","title":"Circular CSSF 26/906","type":"circular","date":"2026-01-20","kind":"circular","html":"<p>Circular CSSF 26/906 is a CSSF circular, published 20 January 2026. Subject: Central administration, internal governance and risk management.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: E-money institutions, Payment institutions.</p>\n<p>Keywords: Internal governance, Payment services.</p>\n<h2>Text</h2>\n<p>Circular CSSF 26/906 Central administration, internal governance and risk management</p>\n<p>In case of discrepancies between the French and the English texts, the French text shall prevail.</p>\n<p>Circular CSSF 26/906 Central administration, internal governance and risk management To all payment institutions and electronic money institutions</p>\n<p>Luxembourg, 20 January 2026 Ladies and Gentlemen, Articles 11(2) and 24-7(2) of the amended Law of 10 November 20009 on payment services (\"LPS\") require payment institutions and electronic money institutions, taking into account the need to ensure the sound and prudent management of the institution, to dispose of robust internal governance arrangements which shall include a clear organisational structure with well-defined, transparent and consistent lines of responsibility, effective processes to identify, manage, monitor and report the risks to which they are or might be exposed to, adequate internal control mechanisms, including sound administrative and accounting procedures as well as control and security arrangements for information processing systems. According to Articles 48-1a and 8(1)(e) of the LPS, the granting and maintaining of the registration of account information service providers requires that the account information service providers dispose of internal governance arrangements and internal control mechanisms including administrative, risk management and accounting procedures, which demonstrate that these internal governance arrangements and internal control mechanisms are proportionate, appropriate, sound and adequate. As a consequence, this circular applies to account information service providers for the purposes of which they shall be treated as payment institutions while applying the principle of proportionality. In the past, the Commission de Surveillance du Secteur Financier (\"CSSF\") has set out the modalities of application of these articles in various circulars. The CSSF has decided to consolidate all the key modalities of application regarding central administration, internal governance and risk management in one single circular. This circular takes into account the European Banking Authority's guidelines on the information to be provided for the authorisation of payment institutions and electronic money institutions and for the registration of account information service providers under Article 5(5) of Directive (EU) 2015/2366 (EBA/GL/2017/09) 1. Circulars IML 95/120, IML 96/126, IML 98/143 and CSSF 04/155 will be repealed for payment and electronic money institutions, and circulars CSSF 11/510 and CSSF 11/520 will be amended. This circular represents a first step towards a consolidated regulatory compilation on internal governance in its broadest sense. It does not cover all the areas of concern such as the information and communication technology (ICT) risk management, the notification of major incidents, remuneration or outsourcing, which are each covered by separate circulars. When, in response to regulatory developments at the European, international, or national level, the CSSF is prompted to specify the requirements set out in this circular, it will update this circular.</p>\n<p>These guidelines are adopted in Luxembourg via Circular CSSF 18/677</p>\n<p>TABLE OF CONTENTS Part I. Definitions and scope ............................................................................................... 5 Chapter 1. Definitions ...................................................................................................... 5 Chapter 2. Scope and proportionality ................................................................................. 6 Part II. Central administration, internal governance and risk management arrangements ............ 7 Chapter 1. Central administration ...................................................................................... 7 Chapter 2. Internal governance arrangements .............................................</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-26-906/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf26_906eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}