AML/KYC in Luxembourg: frameworks, files, remediation

Anti-money-laundering work under the amended Law of 12 November 2004 and CSSF practice, for SMEs, fiduciaries, and regulated businesses — built to survive the moment it is tested: an onboarding refusal, an audit finding, a regulator inspection.

Scope

Framework design. Risk appetite, business-wide risk assessment, policies and procedures proportionate to the organisation — not a copied manual, but a framework the team can actually operate.

Customer files. KYC/KYA documentation standards, UBO identification and the interaction with the RBE (Law of 13 January 2019), source-of-funds and source-of-wealth substantiation, and PEP and sanctions screening arrangements.

Remediation. After findings — internal, audit, or regulator — a sequenced remediation plan: triage of the file population, prioritisation by risk, documentation of what was fixed and why, and the closure report.

Independent file reviews. Where a second pair of eyes is the point, the practice performs AML/KYC file verifications as an assurance engagement — see review, verification & assurance.

Where it connects

AML questions rarely arrive alone: perimeter and authorisation issues sit next to them (compliance), the files live inside corporate routine (company administration), and the workflows are worth automating properly (digitalisation).

For a live question, two paragraphs by email are enough: contact@viekey.eu.