Person standing on bridge viaduct with circular steel construction

Top 5 recurring AML/CFT issues to look out for when preparing for AED onsite inspections

From mere pennies to EUR 5 million. This is the spectrum of single administrative penalties issued by the CSSF in Luxembourg over the past five years. Each stems from onsite inspections which spotlighted serious shortcomings in compliance with legal and regulatory obligations under the AML/CFT Law, Grand-ducal Regulations of 1 February 2010, CSSF Regulation No 12-02 as amended and Circular CSSF 23/842 (complement of complement of Circular CSSF 21/782). Such hefty fines are  examples of the toll of non-compliance.

The Luxembourg Tax Authority – Administration de l’Enregistrement, des Domaines et de la TVA (AED) – plays a similar role in monitoring AML/CFT compliance. Through onsite inspections, the AED ensures that entities under its supervision, such as unregulated alternative investment funds, real estate promotors, accounting professionals, and tax advisors , meet their professional, ethical and AML/CFT obligations. These inspections follow a formal process and can lead to administrative measures or sanctions, including substantial fines.

While AED penalties are generally less severe than those imposed by the CSSF (for example, the total value of collective penalties for administrative sanctions was only just over EUR 480,000),  they remain significant. Companies may face anything from a warning to public naming and shaming, administrative fines of up to EUR 1 million, or even a proposal to withdraw business authorization, subject to the Minister of the Economy’s final decision.

What are some of the most recurring issues? 

Inspections frequently uncover recurring weaknesses, which can be grouped into five key areas:

1. Risk assessment gaps

Many firms fail to consider key risk factors when determining the ML/TF risk level of customers. Additionally, documentation and verification of the source of wealth and source of funds are often incomplete or missing, weakening the overall risk assessment process.

2. Screening and monitoring weaknesses

Automated tools for sanctions and politically exposed persons (PEPs) screening are not used regularly. Related parties such as ultimate beneficial owners (UBOs) and directors are frequently overlooked, creating significant gaps. Furthermore, alerts generated by screening tools are sometimes poorly managed, with delays, lack of second-level compliance checks, and inadequate documentation of alert rejection reasons.

3. Due diligence deficiencies

Client relationships lack clarity regarding their nature and purpose, and expected transactions are not properly recorded. Ongoing due diligence is weak, leading to incomplete analysis of transactions, even in cases linked to previously reported suspicions. Intermediaries acting for multiple clients pose additional risks, particularly when they operate in jurisdictions without equivalent regulatory supervision.

4. Governance and reporting failures

There is insufficient oversight of AML/CFT controls delegated to third parties. Firms frequently fail to report ML/TF suspicions promptly to the Financial Intelligence Unit (FIU). Moreover, compliance functions do not consistently ensure the quality and comprehensiveness of controls performed by the first line of defense.

5. Tax and structural risks

Tax risk indicators are poorly managed, with alerts left unaddressed and plausibility checks missing. The use of SCSp structures for tax optimization is not always properly framed, increasing the risk of misuse for tax fraud. Complex offshore structures often lack clear rationale, heightening exposure to tax-related money laundering.

How do onsite inspections work?

AED inspections follow a structured process:

  • Notification: Companies receive an appointment letter two to three weeks before the visit
  • Preparation: Firms prepare key documents, including risk analyses, client files, and transaction records
  • Inspection: The AML/CFT Officer must be present during the review of compliance areas.
  • Reporting: After the visit, documents are submitted electronically. An initial report is issued within four weeks, highlighting gaps. Firms then have approximately three weeks to respond before the final report and potential sanctions.

Proactive preparation and addressing known weaknesses are essential to minimize risk.

What are the key recommendations for entities when preparing for inspections? 

Entities need to build confidence that their controls can withstand scrutiny. That means keeping documentation current, tightening internal checks, reporting suspicious activity promptly, and investing in smart tools and ongoing staff training. Many firms also lean on trusted professionals to guide them through the process. Why? Because these experts know what regulators look for and can spot weaknesses before they become costly mistakes. 


Summary 

While AED penalties are generally less severe than those imposed by the CSSF,  they remain significant. Companies may face anything from a warning to public naming and shaming, administrative fines of up to EUR 1 million, or even a proposal to withdraw business authorization, subject to the Minister of the Economy’s final decision.

About this article

Authors

Related articles

Final reports on ESMA’s guidelines and RTS: what are the upcoming liquidity management requirements under the new UCITS/AIFMD Framework?

In the context of the transition to the new UCITS/AIFM Directive, ESMA published on 16 April 2025, the final reports on its Guidelines and RTS on liquidity management tools under the AIFMD and UCITS Directive. The RTS was submitted to the Commission, which has 3-4 months to adopt it. Once published in the Official Journal, it is expected to apply on the 20th day following the publication . The Guidelines, in turn, are expected to apply for new funds from the same day as the RTS, meanwhile existing funds will be granted 12 additional months to comply with the new rules.

Know Your Assets: the last update of the CSSF as a wake-up call to all sectors

Know Your Assets (KYA) is a critical process that involves identifying, assessing and managing money-laundering and terrorist financing (ML/TF) risks posed by the investments, to which professionals of the financial sector, in scope of the law of 12 November 2004 on the fight against money laundering and terrorist financing, as well as professionals of the insurance sector, are exposed. The KYA practice is essential not only for compliance with regulatory requirements but also for effective ML/TF risk management.

The AED expands AML/CFT reporting obligations

As part of its mission of monitoring and control in the area of Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT), the Administration de l’Enregistrement, des Domaines et de la TVA (AED) has reinforced its AML/CFT reporting obligations to include all unregulated alternative investment funds (AIFs) in Luxembourg.