Regulatory reporting

SRRC (CSSF Circular 24/854): how to prepare the AML/CFT Summary Report RC, step by step

By the RC Insight team, practitioners who have helped more than 80 fund promoters set up their AML/CFT framework since 2020.

Published Last reviewed: 15 min read

The SRRC (AML/CFT Summary Report RC) is governed by CSSF Circular 24/854 of 29 February 2024. It replaced the former annual RC report for the collective investment sector and applies to financial years ending on or after 31 December 2023. The RC prepares it, the RR submits it on eDesk, and it is due within five months of year-end.

In practice, the SRRC is a structured data return, not a narrative report. Its difficulty lies in the evidence behind each answer: how many account holders, how many PEPs, which controls were outsourced, what was sample-tested, and which findings the RC, the internal auditor, the réviseur d'entreprises agréé and the CSSF raised during the year. This guide walks through the template field by field, as described in the CSSF user guide, and gives the back-planning we use on our own mandates.

Key takeaways

  • The SRRC is the CSSF's mandatory eDesk template for the annual AML/CFT Summary Report RC, governed by CSSF Circular 24/854 of 29 February 2024.
  • It is due within five months after the closing of the annual accounts: 31 May only for a 31 December year-end.
  • The RC prepares it; the RR submits it via eDesk and remains accountable, even if the technical submission is delegated.
  • The template has 15 sections: General Information, Risk Assessment, 12 population sections switched on by the General Information answers, and an AML/CFT Findings register.
  • Start 120 days before the deadline: most of the work is collecting evidence from delegates, auditors and your own sample testing.
On this page
  1. SRRC key facts at a glance
  2. Who must file the SRRC, and who does not
  3. SRRC deadline: five months after year-end, with examples
  4. What the SRRC template contains, section by section
  5. How to prepare the SRRC: a 120-day back-plan
  6. RC vs RR: who does what on the SRRC
  7. Common SRRC mistakes and what the CSSF expects
  8. SRRC vs 21/788 external report vs data collection vs risk assessment
  9. How RC Insight helps
  10. FAQ
  11. Sources

SRRC key facts at a glance

The SRRC is an annual, entity-level eDesk return built around the key data points the CSSF needs for its AML/CFT supervision of the collective investment sector, in line with its data-driven supervision strategy. The table below summarises the rules set by Circular 24/854, the CSSF SRRC FAQ (version 3, 7 October 2024) and the CSSF SRRC user guide (version 1.0, 29 February 2024).

Item Rule Source
Legal basis Article 42(6) and 42(7) of CSSF Regulation No 12-02; CSSF Circular 24/854 of 29 February 2024 Circular 24/854, section 1; user guide
Scope All Luxembourg IFMs (including registered AIFMs), Luxembourg branches of foreign IFMs, and CSSF-supervised investment funds with no Luxembourg IFM filing on their behalf (e.g. self-managed funds, funds with a foreign IFM, ELTIFs) Circular 24/854, sections 1–2; FAQ 1A–1D
Who prepares The RC User guide, section 2.1
Who submits The RR, who may delegate the technical submission but remains accountable; eDesk submitter roles are AML/CFT Responsible, conducting officer or board member Circular 24/854, section 3; FAQ 3A; user guide, section 2.1
Channel Exclusively eDesk: online form in the SRRC module, or a JSON file in a ZIP archive through the CSSF S3 interface; the report can be corrected and resubmitted until the deadline, and only the last submission counts FAQ 3A; user guide, sections 2.2, 4 and 4.1.3
Deadline Within five months after the closing of the annual accounts Circular 24/854, section 3; FAQ 3B
First application Financial years ending on or after 31 December 2023 (with a one-off two-month extension for 31 December 2023 year-ends) Circular 24/854, sections 3–4; FAQ 3B
What it replaced The former annual RC report and the separate annual AML/CFT risk assessment sent to the CSSF FAQ 2B, 2C

Two points are often misread. First, the SRRC is a summary report, not the CSSF's annual financial-crime data collection, which is a separate exercise. Second, there is no fixed calendar date: the deadline moves with each entity's year-end.

Who must file the SRRC, and who does not

The SRRC must be filed by every entity in scope of Circular 24/854. SRRC scope: all Luxembourg IFMs (including registered AIFMs), Luxembourg branches of foreign IFMs, and CSSF-supervised investment funds with no Luxembourg IFM filing on their behalf (e.g. self-managed funds, funds with a foreign IFM, ELTIFs).

The user guide translates this into three entity types that you select in the template: designated IFM, self-managed fund, and fund managed by a foreign IFM. Luxembourg branches of foreign IFMs are in scope of the circular, but the user guide does not say which type they select: check with the CSSF before you start the form.

The exclusions that matter in practice

Circular 24/854 (section 2), relying on Article 42(7) of CSSF Regulation 12-02, waives the filing for Luxembourg investment funds that designated a Luxembourg management company submitting the annual report. The CSSF SRRC FAQ adds four clarifications:

  • Foreign IFM plus Luxembourg UCIA provider (FAQ 1C): a CSSF-supervised fund that appointed a non-Luxembourg IFM but also a Luxembourg IFM providing UCI administration (UCIA) services can be treated as exempt.
  • Change of IFM before filing (FAQ 1E): if a fund had a foreign IFM at year-end but is managed by a Luxembourg IFM at the date of submission, no SRRC is required for the fund.
  • Removal from the CSSF list (FAQ 1F): an entity no longer supervised by the CSSF at the expected date of submission does not have to file.
  • ELTIFs (FAQ 1D): ELTIFs are in scope.

Fund with a ManCo: one report at IFM level

A fund managed by a Luxembourg IFM does not file its own SRRC: the IFM files one report and gives an overall inherent and residual risk assessment for all the funds it services. The fund's RC still has work to do. Under Article 42(6) of CSSF Regulation 12-02, the RC must prepare at least once a year a summary report on his activities for the RR, the authorised management and the board. The CSSF does not expect it automatically, but may request it (FAQ 2A).

RAIFs and unregulated AIFs: the AED, not the CSSF

RAIFs do not file an SRRC. They are supervised for AML/CFT by the AED and send the AED an annual RC report and questionnaire instead; see our guide to the AED RC report for RAIFs.

CSSF or AED? The CSSF supervises for AML/CFT all Luxembourg IFMs (UCITS management companies, authorised AIFMs and registered AIFMs) and CSSF-regulated funds: UCITS, Part II UCIs, SIFs, SICARs and ELTIFs. A RAIF is supervised by the AED for AML/CFT even when its AIFM is CSSF-authorised: the AIFM is supervised by the CSSF, the RAIF by the AED. Two entities, two supervisors, two sets of obligations. An AIFM managing both SIFs and RAIFs therefore files an SRRC with the CSSF, while each RAIF reports separately to the AED. The full decision logic is in CSSF vs AED supervision.

SRRC deadline: five months after year-end, with examples

SRRC deadline: within five months after the closing of the annual accounts, submitted exclusively via eDesk. It is not a fixed calendar date (31 May only for a 31 December year-end). The report can be updated and resubmitted until the deadline; only the last report submitted for a given year-end counts, and no modification is possible once the five months have lapsed (user guide).

Financial year-end SRRC due by Start preparation (T-120 days) Board acknowledgment of findings (T-30, recommended)
31 December 2025 31 May 2026 31 January 2026 1 May 2026
31 March 2026 31 August 2026 3 May 2026 1 August 2026
30 June 2026 30 November 2026 2 August 2026 31 October 2026
30 September 2026 28 February 2027 31 October 2026 29 January 2027

The T-120 and T-30 milestones are RC Insight recommended practice, not legal deadlines; where a milestone falls on a weekend or public holiday, use the next business day. With several mandates and year-ends, add the 21/788 external reports (six months) and the AED deadlines for RAIFs (31 May, a date the AED confirms each year): one calendar is the only reliable control.

What the SRRC template contains, section by section

The SRRC template has 15 sections. In the order of the CSSF user guide: General Information, Risk Assessment, Investment Fund Managers, Funds, Investors, AML/CFT Blocked Investors, Third-party Distributors, Third-party Initiators, External Portfolio Managers, Intermediaries, Third-party Investment Advisors, PEPs, Assets, Branches/Subsidiaries and AML/CFT Findings.

The template is conditional. The General Information section asks, for each population, whether you are responsible for due diligence, how many relationships you have, whether you outsourced the due diligence, and whether you performed the due diligence and the oversight of outsourced controls. Each "yes" switches on a detailed section. The descriptions below come from the CSSF user guide (sections 3–4 and Annexes I–II).

General Information

This section defines your profile and drives the rest of the report. It covers: type of entity; due diligence on your IFM (for a fund managed by a foreign IFM); funds serviced (whether you or your group initiated all of them, how many, outsourcing, due diligence and oversight); investors; third-party distributors; third-party initiators; external portfolio managers; third-party investment advisors; intermediaries ("nominees"); PEPs; assets; branches and subsidiaries. It ends with the board confirmation described below.

Three counting rules from the CSSF guidance cause most errors:

  • Investors are counted as account holders. An investor holding seven positions, or positions in several funds, counts once: what you count is the number of KYC files.
  • "Third-party" means outside your group. Group distributors, initiators and investment advisors are not counted as third parties. External portfolio managers are the exception: their count includes group entities.
  • PEPs are counted as at the end of the reference period, at account-holder level: the investor counts if the investor, or its beneficial owner or representative, is a PEP.

A fund reporting in its own name enters 0 as the number of funds serviced.

Risk Assessment

This section replaces the separate annual risk assessment previously sent to the CSSF. It asks for your ML/TF risk appetite, your overall inherent and residual ML/TF risk for the funds you service, and whether triggers modified the inherent risk during the period. The CSSF uses a four-level scale: Low, Medium-Low, Medium-High, High. If you use a three-level scale, report your Medium as Medium-High. Trigger categories are fund services, geography, licence, investors, assets, type of funds, volume of assets, business model, and others (with free text).

The annual ML/TF risk assessment no longer has to be filed with the SRRC, but it must still be performed and documented. The SRRC only carries its conclusions.

The population sections

Each population section follows the same pattern: did you perform sample testing during the reference period; if yes, the sample size; if no, how long ago the last sample test was performed (never, one, two, three or more than three years); in most sections, the review frequency of high residual risk files (every year or less, every two years, every three years or more); and whether your work produced AML/CFT findings. The CSSF defines sample testing as a document-based review (KYC documents, proof of screening) and lets you count as sample all AML/CFT due diligence files performed or reviewed during the period (FAQ 2E).

Template section Switched on when Specific data requested Evidence the RC must collect
Investment Fund Managers Due diligence performed on the IFM (funds) Sample testing, size, findings IFM due diligence file, annual IFM questionnaire, oversight minutes
Funds Due diligence or oversight on funds Sample testing, size, review frequency, findings List of funds and sub-funds serviced, initiator files, fund-level risk ratings
Investors Due diligence or oversight on investors Number of high residual risk investors, sample testing, review frequency, findings Register/TA extract at year-end, risk-rating distribution, EDD file list, periodic review status, screening logs
AML/CFT Blocked Investors Investor count above zero Percentage of blocked investors; shortcomings in remediation plans TA blocked-account report, remediation plan, ageing analysis
Third-party Distributors Due diligence or oversight on distributors Sample testing, size, review frequency, findings Distributor list with group/third-party flag, distributor due diligence questionnaires
Third-party Initiators Due diligence or oversight on initiators Sample testing, size, review frequency, findings Initiator KYC files, onboarding approvals
External Portfolio Managers Due diligence on external portfolio managers Sample testing, size, review frequency, findings Delegation agreements, delegate due diligence files
Intermediaries Due diligence or oversight on nominees Sample testing, size, review frequency, findings Nominee list from the register, nominee due diligence and AML/CFT side letters
Third-party Investment Advisors Due diligence on advisors Sample testing, size, review frequency, findings Advisory agreements, advisor due diligence files
PEPs Due diligence or oversight on PEPs Sample testing, size, findings PEP list at year-end, senior-management approvals, screening hits and dispositions
Assets Due diligence or oversight on assets Investment in high-risk assets (per your self-assessment), sample testing, frequency, findings Asset due diligence files, target/seller/counterparty screening, asset risk scoring
Branches/Subsidiaries Branches or subsidiaries perform AML/CFT controls or are overseen Sample testing, size, findings Group oversight reports, branch control testing

For blocked investors, the CSSF guidance allows you to reuse the statistics previously computed for point 318(f) of Circular 18/698. If a remediation plan is impossible (for example, deceased investors), explain it in the comments.

AML/CFT Findings

This section is the register of the year's AML/CFT findings. You report every finding from previous reference periods that is still open during the period covered, and every finding identified during that period, whether open or closed (FAQ 2D). Sources are the RC, the internal auditor (reports to the board), the réviseur d'entreprises agréé (management letter) and the CSSF (correspondence to the entity). For each finding, the template asks for:

Field Values (Annex II)
Identifier Tracking code of a finding reported in a previous SRRC; left blank for a new finding
Detected by RC, RR, CSSF, statutory auditor, internal auditor, other
Severity Less significant, moderately significant, significant, very significant
Related section IFM, funds, investors, blocked investors, distributors, initiators, external portfolio managers, investment advisors, intermediaries, PEPs, assets, branches, other
Action(s) taken Free text ("None" if none)
Status Open, closed

Keep the tracking codes from year to year. On the S3 channel, a reference to a prior finding that cannot be retrieved is rejected (validation code SRRC013).

Board confirmation

The General Information section ends with a confirmation that the findings in the report have been presented to and acknowledged by the board of directors, board of managers or equivalent. The acknowledgment concerns the findings of this year's report and must be obtained before filing: tick the box only when the board minutes or circular resolution show it.

How to prepare the SRRC: a 120-day back-plan

Preparing the SRRC takes about four months if the evidence is held by delegates. The procedure below is back-planned from the deadline (T = SRRC due date); it is the one we use on our own mandates.

  1. T-120: Confirm scope and eDesk access. Check the entity type against Circular 24/854 and FAQ 1A–1F. Confirm who will submit (an eDesk user with the AML/CFT Responsible, conducting officer or board member role), check LuxTrust validity, and choose between the online form and the S3 upload.
  2. T-110: Freeze the year-end data perimeter. Obtain from the transfer agent or registrar a year-end extract: account holders (deduplicated), nominees, PEPs at account-holder level, risk-rating distribution and blocked accounts. List funds serviced and every distributor, initiator, external portfolio manager and advisor, flagged group or third party.
  3. T-100: Map who did what. For each population, document whether the due diligence was performed in-house or outsourced, and what oversight you performed on outsourced controls. This decides which sections open and what you can defend.
  4. T-90: Update the ML/TF risk assessment. Confirm the risk appetite, the overall inherent and residual risk on the four-level scale, and the triggers of the year. Have the underlying assessment documented and approved.
  5. T-75: Close the sample testing. Consolidate, per population, the files reviewed during the period, the sample size, the date of the last test, the review frequency applied to high residual risk files, and the results.
  6. T-60: Build the findings register. Collect RC findings, internal audit reports, the réviseur's management letter and CSSF letters. Carry forward open findings with their tracking codes, and assign detected-by, severity, related section, actions and status.
  7. T-45: Prepare the internal RC report. Draft the additional RC work the board and the RR may require alongside the SRRC, covering items the SRRC does not carry, such as STRs filed with the CRF, refused business relationships and training. These data points stay internal and are not sent to the CSSF (FAQ 2B).
  8. T-30: Present to the RR and the board. Present the findings and the draft SRRC data; minute the board's acknowledgment of this year's findings, which the board confirmation field requires before filing.
  9. T-14: Enter and validate on eDesk. Enter the data or upload the ZIP file, run the validation, and correct any error. On S3, wait for the feedback file before sending a new file for the same entity.
  10. T-7: Submit and archive. Submit, check the status shows "SUBMITTED", export the PDF, and file it with the evidence pack. Resubmit before the deadline if a correction is needed.

RC vs RR: who does what on the SRRC

The RC prepares the SRRC. The RR submits it and remains accountable, even if the technical submission is delegated. The board confirms that it acknowledged the findings.

Step RC RR Board
Collect evidence, run sample testing, compile findings Responsible Informed —
Risk assessment conclusions Prepares Validates Approves risk appetite
Findings and remediation Reports and tracks Owns remediation Acknowledges
eDesk submission May be the technical submitter if authorised Submits, or delegates with documented authorisation —
Internal RC report supplementing the SRRC (FAQ 2B) Prepares and presents May require it; receives it May require it; receives it

A delegation of the technical submission is permissible to an eDesk user linked to the entity with the "AML/CFT responsible" role, provided it is documented in writing and made available to the CSSF on demand (FAQ 3A). Where the RC is an external third party, record it for instance in the RC engagement letter or a board resolution. The RR stays ultimately responsible.

Common SRRC mistakes and what the CSSF expects

The CSSF built the SRRC around a few supervisory questions: do you know your populations, do you control what you outsourced, do you test, and do you fix what you find. Most mistakes we see in reviews come from answering the form without the evidence behind it.

  • Counting positions instead of account holders. The CSSF guidance is clear that an investor counts once, across all funds.
  • Counting group entities as third parties. Only distributors, initiators and investment advisors outside your group count; external portfolio managers include group entities.
  • Answering "yes" to oversight without an oversight file. Receiving a KPI pack from the transfer agent is not oversight. Keep your review notes, sample results and escalations.
  • Incomplete findings. Forgetting the réviseur's management letter, internal audit points or last year's open findings. Every AML/CFT finding in those sources belongs in the register.
  • Breaking the tracking chain. Re-entering an old finding as new instead of using its tracking code.
  • Inconsistent risk answers. A residual risk above the declared appetite, with no finding or action plan, will raise questions.
  • Ticking the board box before the board meeting. Plan the SRRC on the agenda of the board that approves the accounts.
  • Filing late in the window. LuxTrust renewals, role assignments and S3 feedback files all take time.
  • Sending a separate RC report by email. The CSSF states it does not expect an additional RC report through other channels from entities in scope (FAQ 2B).

Keep your SRRC figures consistent with the CSSF's annual financial-crime data collection and with the 21/788 external report. All three describe the same entity over the same year.

SRRC vs 21/788 external report vs data collection vs risk assessment

The SRRC is one of several annual AML/CFT deliverables, each with its own author, addressee and deadline.

Document Author Addressee Deadline Channel
SRRC (Circular 24/854) RC prepares; RR submits CSSF Within five months after year-end eDesk (form or S3)
Internal RC report supplementing the SRRC (entities in scope) RC Board and RR, who may require it With the SRRC cycle Internal; its data points are not sent to the CSSF (FAQ 2B)
Annual RC summary report (Art. 42(6) RCSSF 12-02) of a fund whose Luxembourg IFM files the SRRC RC RR, authorised management, board At least annually Internal; CSSF on request (FAQ 2A)
External AML/CFT report (Circular 21/788) Réviseur d'entreprises agréé CSSF Within six months after year-end eDesk
Annual financial-crime data collection Luxembourg IFM, or fund without a Luxembourg IFM (self-managed or with a foreign IFM) CSSF Set each year by CSSF circular letter eDesk
ML/TF risk assessment Entity (RC drafts) Board Annual, documented Not filed; conclusions go into the SRRC
AED RC report (RAIFs) RC AED 31 May (confirmed by the AED each year) Signed PDF to aed.raif@en.etat.lu

CSSF Circular 21/788 (17 December 2021): annual AML/CFT external report by the réviseur d'entreprises agréé, due within six months after year-end via eDesk. Funds that have designated an IFM, established in Luxembourg or abroad, are exempt from filing it (section 1.2).

CSSF annual financial-crime data collection: for reference year 2025, Luxembourg IFMs and funds without a Luxembourg IFM (self-managed or with a foreign IFM) completed the AMLA data-collection templates on eDesk (launched 2 March 2026). Deadlines were 22 April 2026 (entities in AMLA's calibration sample) and 22 May 2026 (all others). Dates change every year: always check the CSSF circular letter.

How RC Insight helps

RC Insight is software built for the RC. It consolidates the year's evidence across all your mandates (transfer agent KPIs, screening results, risk ratings, sample testing, delegate oversight and a findings register with persistent tracking codes) and turns it into a board-ready RC report aligned with the SRRC template. Each SRRC answer links back to the evidence behind it, and the calendar tracks every year-end, SRRC, 21/788 and AED deadline across your funds.

Request a demo to see an SRRC prepared from a year of RC work.

FAQ

What is the SRRC?

The SRRC (AML/CFT Summary Report RC) is the CSSF's mandatory annual template for the RC's summary report in the collective investment sector, governed by Circular 24/854 of 29 February 2024. It is filed on eDesk and covers populations, outsourcing and oversight, sample testing, the risk assessment and AML/CFT findings.

When is the SRRC due?

The SRRC is due within five months after the closing of the annual accounts. It is not a fixed calendar date: 31 May applies only to a 31 December year-end, 30 November to a 30 June year-end. The report can be corrected and resubmitted until the deadline, but not after.

Who submits the SRRC?

The RC prepares the SRRC and the RR submits it via eDesk. The RR may delegate the technical submission to another authorised eDesk user, but remains ultimately responsible. No other channel than eDesk is accepted by the CSSF under Circular 24/854.

Does a fund with a ManCo file its own SRRC?

No. A Luxembourg fund that designated a Luxembourg management company submitting the report is excluded from Circular 24/854; the IFM files one SRRC covering the funds it services. The fund's RC must still prepare the annual internal summary report under Article 42(6) of CSSF Regulation 12-02, which the CSSF may request.

Is the risk assessment attached to the SRRC?

No. The CSSF FAQ confirms that the annual AML/CFT risk assessment no longer has to be sent to the CSSF, because its content is included in the SRRC's Risk Assessment section. The assessment itself must still be performed, documented and approved each year, and its conclusions drive the SRRC answers.

Does the SRRC apply to RAIFs?

No. RAIFs are supervised for AML/CFT by the AED, even when their AIFM is CSSF-authorised. They file the AED annual AML/CFT questionnaire and a signed RC report by 31 May. The AIFM itself, if Luxembourg-based, files its own SRRC with the CSSF.

What happens if the SRRC is late?

Missing the SRRC deadline is a failure to meet the filing obligation of Circular 24/854, and the eDesk report can no longer be modified once five months have lapsed. As an illustration of CSSF practice on other AML/CFT filings, the CSSF fined nine AIFMs EUR 10,000 each for not filing the 2024 AML/CFT questionnaire.

Sources