RC function

Responsable du Contrôle (RC) in Luxembourg: the complete guide for investment funds

By the RC Insight team, practitioners who have helped more than 80 fund promoters set up their AML/CFT framework since 2020.

Published Last reviewed: 21 min read

The Responsable du Contrôle (RC) is the AML/CFT compliance officer that every Luxembourg investment fund and investment fund manager must appoint. The RC implements the fund's anti-money laundering and counter-terrorist financing framework, tests it, escalates suspicions to the CRF and reports every year to the board and the supervisor.

Definition. Luxembourg professionals subject to AML/CFT obligations must appoint a person responsible for compliance at management level (the RR, Responsable du Respect des obligations) and a compliance officer (the RC, Responsable du Contrôle du respect des obligations), under Article 4(1) of the amended Law of 12 November 2004. For funds, the RC is the operational owner of AML/CFT controls; the RR is the accountable owner.

This guide is written from the RC's desk, not from a law library. It covers the legal basis, the RR/RC split, who must appoint and who can serve, how the appointment is notified to the CSSF or the AED, and, above all, what an RC actually delivers across a year.

Key takeaways

  • Every Luxembourg investment fund and every investment fund manager subject to AML/CFT supervision must appoint both an RR and an RC (Art. 4(1) AML Law).
  • The RR sits at management or board level and is accountable; the RC is the compliance officer who runs and tests the AML/CFT framework day to day.
  • The RC may be a board member, an employee of the AIFM or an external third party, but a single board member appointed as RR cannot also be RC of a RAIF.
  • CSSF-supervised entities notify RR/RC through the AML/CFT Market Entry Form on eDesk; AED-supervised RAIFs and AIFs use the AED RR/RC identification form.
  • The RC's year ends in a regulatory report: the SRRC for CSSF entities (within five months of year-end) or the AED RC report and questionnaire for RAIFs (31 May).
On this page
  1. What is the difference between the RR and the RC?
  2. What is the legal framework for the RC in Luxembourg?
  3. Who must appoint an RR and an RC: the fund, the manager, or both?
  4. Who can be the RC of a Luxembourg fund?
  5. How is the RC appointed and notified to the CSSF or the AED?
  6. What does an RC do? The RC's year in deliverables
  7. Internal, outsourced or shadow RC: which model fits your fund?
  8. Which RC pitfalls do supervisors and auditors find most often?
  9. What are the sanctions and the current supervisory focus?
  10. How RC Insight helps
  11. Frequently asked questions
  12. Sources

What is the difference between the RR and the RC?

The RR is accountable for AML/CFT compliance at management level; the RC is the compliance officer who implements and controls it. Both roles are mandatory, they are distinct, and in a RAIF a single board member designated as RR cannot also act as RC.

Think of the RR as the owner and the RC as the operator. The RR (or the board acting collegially) approves the policy, the risk appetite and the resources. The RC turns them into procedures, controls, files and reports, and tells the RR when something is not working.

RR: Responsable du Respect des obligations RC: Responsable du Contrôle du respect des obligations
Legal basis Art. 4(1) Law of 12 November 2004; Art. 40 CSSF Regulation No 12-02 Art. 4(1) Law of 12 November 2004; Art. 40 and 42 CSSF Regulation No 12-02
Level Management level: authorised management or board of directors (Art. 40 CSSF Reg. 12-02) Compliance officer at an appropriate hierarchical level, with the authority and access needed to control
Who can hold it (fund) The board of directors (or the board of managers of the general partner) acting as a collegial body, or one designated board member A board member, an employee of the AIFM, or an external third party (outsourced RC)
Core responsibilities Adopts and oversees the AML/CFT policy, allocates resources, receives RC reporting, submits the SRRC and remains accountable for it Implements policies and procedures, performs and tests controls, oversees delegates, handles alerts and suspicious transaction reports, prepares the annual RC report or SRRC
Contact with the supervisor Must be reachable by the Luxembourg AML/CFT authorities Must be available to the authorities; for RAIFs, the AED treats the RC as the RAIF's main contact person
Notification CSSF: AML/CFT Market Entry Form (eDesk). AED: RR/RC identification form Same channels as the RR, at first appointment and after any change
Incompatibility If a single board member is RR of a RAIF, that member cannot also be its RC (AED) Same rule, seen from the RC side: the RC of a RAIF cannot be the single board member designated as RR (AED)

For a deeper look at the division of tasks and the board's role, the CSSF FAQ on persons involved in AML/CFT for a Luxembourg investment fund or IFM remains the reference text on the fund side.

The RC exists because Article 4(1) of the amended Law of 12 November 2004 requires it. CSSF Regulation No 12-02 (Articles 40 and 42) sets the conditions and duties for CSSF-supervised entities, and the CSSF and AED FAQs apply them to funds.

The layers that matter for an RC:

  • Law of 12 November 2004 on the fight against money laundering and terrorist financing (the AML Law), Article 4(1). Requires the professional to appoint an RR at management level and an RC at an appropriate hierarchical level. Paraphrased here; read the consolidated text on the CSSF website or on Legilux.
  • CSSF Regulation No 12-02, as amended by CSSF Regulation No 20-05 of 14 August 2020. Article 40 places the RR at the level of the authorised management or board and allows investment fund managers (IFMs) and investment funds to appoint a third party as RC. Article 40(3) requires relevant professional experience, knowledge of the Luxembourg AML/CFT framework and sufficient authority, including timely access to all customer and transaction data. Article 42 gives the compliance officer the power to propose to management, on its own initiative, any measure needed to apply the AML/CFT policy.
  • CSSF FAQ "Persons involved in AML/CFT for a Luxembourg Investment Fund or Investment Fund Manager" (November 2019, updated March 2021). Explains who may act as RR and RC in a fund and an IFM, and the contractual terms required when the RC is external.
  • AED guidance for RAIFs (AED RAIF guide, March 2023, and the AED RR/RC FAQ). Applies the same model to AED-supervised funds and adds the RR/RC incompatibility rule.
  • Reporting circulars. CSSF Circular 24/854 (SRRC) for CSSF-supervised entities; the AED RC report and questionnaire for RAIFs.

What changes with AMLR in 2027?

The EU AML Regulation (AMLR), Regulation (EU) 2024/1624, applies from 10 July 2027. AMLR Article 11 requires a management-body member responsible for AML/CFT compliance and a compliance officer with sufficiently high hierarchical standing. This broadly mirrors the Luxembourg RR/RC model, so the two roles survive; what changes is the rulebook they apply, which moves from national law to a directly applicable regulation. AMLR treats AIFs and their AIFMs, and UCITS and their management companies, as obliged entities. AMLA, based in Frankfurt, starts direct supervision of selected entities on 1 January 2028. We map the article-by-article impact in AMLR 2027 impact on Luxembourg funds.

Who must appoint an RR and an RC: the fund, the manager, or both?

Both. Every Luxembourg investment fund and every investment fund manager subject to AML/CFT supervision must appoint both an RR and an RC. The fund's obligations are its own: the AED states that the AIFM's compliance "never exempts" a RAIF from its own AML/CFT obligations.

This is the point most often misunderstood by promoters coming from other jurisdictions. A RAIF managed by a CSSF-authorised AIFM has two sets of AML/CFT obligations: the AIFM's, supervised by the CSSF, and the RAIF's, supervised by the AED. The AIFM's RC does not automatically cover the fund. The fund's board must designate its own RR and RC, even if, in practice, the fund's RC is a member of the AIFM's staff.

Which supervisor applies: CSSF or AED?

The supervisor depends on the fund's regime, not on the manager's.

Entity AML/CFT supervisor RR/RC notification
UCITS management companies, authorised AIFMs, registered AIFMs CSSF AML/CFT Market Entry Form (eDesk)
UCITS, Part II UCIs, SIFs, SICARs, ELTIFs CSSF AML/CFT Market Entry Form (eDesk)
RAIFs AED AED RR/RC identification form
Other Luxembourg AIFs not prudentially supervised by the CSSF (e.g. unregulated SCSp, SCS, SCA) AED AED RR/RC identification form

The CSSF supervises for AML/CFT all Luxembourg IFMs (UCITS management companies, authorised AIFMs and registered AIFMs) and CSSF-regulated funds: UCITS, Part II UCIs, SIFs, SICARs and ELTIFs. The AED supervises RAIFs and other Luxembourg AIFs not prudentially supervised by the CSSF (e.g. unregulated SCSp/SCS/SCA AIFs), under Articles 2-1(8), 1(3a)(e) and 2(1) point 7 of the AML Law. A RAIF is supervised by the AED for AML/CFT even when its AIFM is CSSF-authorised: two entities, two supervisors, two sets of obligations. Edge cases (de minimis managers, foreign AIFMs, umbrella structures) are covered in CSSF vs AED supervision.

Who is the RR and RC of an SCSp?

An SCSp has no board of its own: it acts through its general partner, so its RR sits at general partner level. The RR is the board of managers of the general partner acting collegially, or one of its managers. The general partner then designates the RC, who may be a manager, an employee of the AIFM or an external RC.

Where the general partner is also the fund's registered (de minimis) AIFM, an RC must be appointed at both levels: at the general partner, in its capacity as registered AIFM, and at the SCSp. This is the case most often missed: an authorised AIFM, as a CSSF-supervised professional, always has its own RC, whereas a general partner that is also a registered AIFM may not realise that it needs one in both capacities. An unregulated SCSp AIF falls under AED supervision; an SCSp that is a SIF or a RAIF follows its regime.

Who can be the RC of a Luxembourg fund?

The RC may be a board member, an employee of the AIFM, or an external third party (outsourced RC). If the board appoints a single member as RR, that person cannot also be the RC (AED guidance for RAIFs). Whoever holds the role must meet the fit-and-proper conditions.

What are the three options?

  1. A board member as RC. Common in small structures. It works when the director has real AML/CFT expertise and time, and when the board has designated the RR as the collegial board or another member.
  2. An employee of the AIFM. Frequent when a third-party AIFM or a group AIFM services several funds. The appointment must still be made by the fund's board, personally, for that fund.
  3. An external RC. An independent professional or a firm providing the RC service. The CSSF FAQ requires the contract to name the individual RC, to subject any replacement to the board's approval and to be acknowledged in writing. The fund appoints a person, not a firm.

The CSSF FAQ also states that the RC must, as a principle, be available in Luxembourg, with an exception where the IFM and the RC are not domiciled in Luxembourg.

What does "fit and proper" mean for an RC?

RR and RC must have relevant professional experience, knowledge of the Luxembourg AML/CFT framework, and sufficient authority, including timely access to all customer and transaction data (Art. 40(3) CSSF Reg. 12-02). The CSSF and AED FAQs add three practical tests for the RC:

  • Demonstrable AML/CFT expertise, evidenced by training and work experience;
  • Knowledge of the fund's investments and distribution strategy, because an RC who does not understand a private debt portfolio cannot assess its asset-side risk;
  • Immediate availability to the authorities and access to all internal documents and systems needed to perform the role.

Article 40(3) also refers to the availability necessary for the effective and autonomous exercise of the function. Neither the CSSF FAQ nor the AED FAQ sets a numerical cap on RC mandates, so capacity is a question of evidence: time allocated, team, tools.

How is the RC appointed and notified to the CSSF or the AED?

The board appoints the RC by resolution, then notifies the supervisor. CSSF-supervised funds and IFMs use the AML/CFT Market Entry Form on eDesk; AED-supervised RAIFs and AIFs use the AED RR/RC identification form, at first appointment and after every change.

CSSF route. CSSF-supervised funds and IFMs notify their RR and RC through the AML/CFT Market Entry Form on eDesk at set-up. Changes must be communicated to the CSSF in advance. The Market Entry Form carries the identification documents of the persons concerned.

AED route. AED-supervised RAIFs and other AIFs notify their RR and RC with the AED RR/RC identification form, at first appointment and after any change. The AED page asks for the form to be sent without delay to AED.finvehicles@en.etat.lu, unsigned, as the completed fillable PDF form in its original format (2 MB maximum; a scan of the printed form is not accepted), together with the signed board minutes or circular resolutions.

A practical sequence we use at set-up:

  1. Board resolution appointing the RR (collegial board or named member) and the RC (named individual), with effective date.
  2. RC engagement letter or mandate (for an external RC: individual named, replacement subject to board approval, written acknowledgement).
  3. Notification: Market Entry Form (CSSF) or RR/RC identification form (AED).
  4. Registration of the RC on goAML so that suspicious transaction reports can be filed from day one.
  5. Onboarding of the RC to the delegates: data access, reporting lines, escalation contacts.

What does an RC do? The RC's year in deliverables

An RC delivers a documented annual cycle: a policy and a risk assessment approved by the board, a monitoring plan, controls on investors, assets and delegates, training, escalation of suspicions, periodic board reporting and an annual report to the supervisor. The table below is the backbone of that cycle.

Across the more than 80 fund promoters we have helped set up their AML/CFT framework since 2020, the funds that pass inspections without findings are not those with the thickest policy. They are those whose RC can produce, for each deliverable, the evidence that it was done, when and by whom.

Deliverable Frequency Owner Evidence to keep
AML/CFT policy and procedures review Regular review by the RC and internal audit (Art. 38(4) CSSF Reg. 12-02): annually, and after any regulatory or structural change RC drafts; board/RR approves Versioned policy, change log, board minutes
ML/TF/PF risk assessment and Risk Appetite Statement (RAS) Annually, and on material change RC prepares; board approves Dated assessment, scoring methodology, approved RAS
RC monitoring plan Annually, at the start of the cycle RC; presented to the board Approved plan with control list, sample sizes, timing
Investor due diligence reviews Ongoing; periodic reviews by risk level Delegate (TA/central administration) performs; RC controls Sample-testing workpapers, exceptions log, remediation tracker
Asset due diligence Before each investment and on an ongoing basis Portfolio manager/AIFM performs; RC reviews KYA file per asset, risk score, approval trail
Delegate oversight (KYD) Regular control of the delegate (Art. 37(2) CSSF Reg. 12-02): at onboarding, then at least annually RC Due diligence questionnaire, review report, follow-up actions
Training Regular, documented continuing training (Art. 46 CSSF Reg. 12-02): annually, and on joining RC organises Content, attendance records, test results
Suspicious transaction escalation Event-driven, without delay RC files via goAML (RR if the RC is unavailable) Internal alert log, analysis, goAML reference
Board reporting Written reports on a regular and ad hoc basis (Art. 42(5)) and a summary report at least once a year (Art. 42(6) CSSF Reg. 12-02); quarterly recommended RC reports to board/RR RC report, board minutes, action tracker
Annual regulatory report Yearly: SRRC within five months of year-end (CSSF); RC report and questionnaire by 31 May, a date the AED confirms each year (AED, RAIFs) SRRC: RC prepares, RR submits. AED: RR sends the questionnaire (may delegate it to the RC), RC sends the RC report eDesk submission receipt or AED email, signed report
Supervisory data collections Yearly, dates set by circular letter RC coordinates Submitted templates, supporting data

Frequencies marked "practice" are RC Insight house methodology, not legal requirements. The legal requirement is that each control is risk-based, performed and documented.

Review the AML/CFT policy and procedures

The policy is the RC's contract with the board. It states who does what (fund, AIFM, central administration, transfer agent, portfolio manager), which due diligence applies to which risk level, and how exceptions are approved. We review it every year and after any trigger: a new delegate, a new strategy, a new CSSF circular, a finding. The deliverable is not the document; it is the board resolution approving a version whose changes are traceable.

Update the ML/TF/PF risk assessment and the RAS

The annual ML/TF risk assessment no longer has to be filed with the SRRC, but it must still be performed and documented. It should score the fund's own exposure (investors, distribution channels, assets, geographies, delegates) against the national and sectoral picture: the CSSF Sub-sector Risk Assessment for the Collective Investment Sector (Update 2025) rates residual ML risk Medium for UCITS ManCos and AIFMs and residual TF risk Low, and Luxembourg published its 2025 National Risk Assessment of Money Laundering on 26 May 2025. The RAS translates the result into limits the board accepts. Method and scoring grid: ML/TF/PF risk assessment and RAS.

Build the RC monitoring plan

The monitoring plan is where the RC's year becomes testable. It lists each control, its frequency, the sample size, who performs it and when results go to the board. Without a plan, an RC reacts; with one, an RC can show a supervisor what was tested and why. Template and sampling logic: RC monitoring plan.

Control investor due diligence

In most funds the transfer agent or central administrator performs investor KYC. The RC does not redo the files: it tests them. We sample onboarding and periodic-review files by risk level, check beneficial-owner identification, PEP and sanctions screening, source of funds for higher-risk investors, and follow each exception to closure. RC Insight methodology recommends CDD updates annually for high risk, every 3 years for medium risk and every 5 years for low risk. Details: investor KYC for Luxembourg funds.

Perform or review asset due diligence

The CSSF published an FAQ on AML/CFT asset due diligence on 13 December 2024: a risk-based approach, with an initial risk assessment required for unlisted assets. For private equity, venture capital, real estate and private debt, this means screening the target, the seller, co-investors and counterparties, and documenting the risk score before the investment committee decides. The RC checks that it happened and that red flags were escalated. Method: asset due diligence (KYA).

Oversee delegates (KYD)

A fund delegates AML/CFT tasks; it does not delegate the responsibility. The AED expects the RC report of a RAIF to cover the controls performed on services provided by third parties such as the AIFM, central administration, transfer agent and depositary. Our standard: a due diligence questionnaire at onboarding, an annual review with evidence requested (procedures, sample outputs, incident log, audit findings), and follow-up actions tracked to closure. Questionnaire and review programme: delegate oversight (KYD).

Organise AML/CFT training

CSSF Regulation 12-02 (Article 46) requires ongoing training and awareness for all staff, including the members of the management bodies and authorised management, adapted to the participants' needs. For a fund, that means the board, the RR and the delegate teams who handle the fund's investors and assets. Content should cover fund-industry typologies, not generic banking scenarios. Keep attendance and content: an inspector will ask for both.

Escalate suspicions to the CRF through goAML

Suspicious transaction and activity reports go to the CRF (Cellule de renseignement financier) exclusively through goAML. The CRF updated its reporting guidelines (v2.2) on 6 January 2026. The AED guide states that the RC usually files, and that the RR must do so if the RC is not available. The RC's deliverable is a clear internal escalation route from delegates to the RC, an analysis file for every alert, and a decision (report or not) that is reasoned and dated.

Report to the board

The board is accountable, so it must be informed. We report quarterly: status of the monitoring plan, exceptions and remediation, delegate issues, alerts and suspicious transaction reports (in aggregate), regulatory changes, and decisions needed. Board minutes that record the discussion, not just "the RC report was noted", are one of the first things an inspector reads.

File the annual RC report: SRRC or AED RC report

For CSSF-supervised entities, the SRRC (AML/CFT Summary Report RC) is governed by CSSF Circular 24/854 of 29 February 2024. It is due within five months after the closing of the annual accounts, submitted exclusively via eDesk. The RC prepares the SRRC; the RR submits it and remains accountable, even if the technical submission is delegated. Walkthrough: SRRC step-by-step guide.

For RAIFs, the annual AML/CFT questionnaire (Excel, data as at 31 December) and the annual RC report (signed PDF) are due by 31 May (a date the AED confirms each year), sent to aed.raif@en.etat.lu. The RR sends the questionnaire and may delegate this to the RC; the RC sends the RC report. The AED RC report must cover at least a dozen topics, including the risk assessment, due diligence on investors, initiators and portfolio managers, PEPs, asset due diligence, suspicious transaction reports to the CRF, sanctions/freezing reports and breaches identified. For other unregulated AIFs, the questionnaire is filed on AED invitation; the absence of an invitation does not exempt a fund from its legal obligations. Details: AED RC report and AML/CFT questionnaire.

What does the RC calendar look like for a 31 December year-end?

Indicative sequence for a fund with a 31 December financial year-end. Always check the current CSSF circular letters and AED pages: data-collection dates change every year.

Period CSSF-supervised fund or IFM AED-supervised RAIF
January–February Close prior-year monitoring plan; update risk assessment; approve new monitoring plan Same; extract data as at 31 December for the AED questionnaire
March–May Annual CSSF financial-crime data collection (dates set by circular letter); prepare SRRC Prepare RC report and questionnaire; submit by 31 May
By 31 May SRRC due (five months after a 31 December year-end) AED RC report and questionnaire due
By 30 June 21/788 external report due for IFMs and for funds without an IFM (six months after year-end) Not applicable
July–September Delegate reviews; mid-year sample testing Delegate reviews; mid-year sample testing
October–December Training; policy review; next-year planning and budget Training; policy review; next-year planning and budget

Internal, outsourced or shadow RC: which model fits your fund?

All three models are lawful if the appointed RC meets the fit-and-proper conditions. The choice depends on the fund's size and complexity, the in-house AML/CFT expertise available, and how much independence the board wants between the RC and the business.

A "shadow RC" is not a legal status. It describes an experienced RC who supports, reviews or backs up an internally appointed RC without holding the appointment. Accountability stays with the appointed RC and the RR.

Internal RC (board member or AIFM employee) Outsourced RC (external third party) Shadow RC (support to an internal RC)
Who holds the appointment Director or AIFM staff member Named external individual, under contract The internal RC; the shadow RC advises
Strengths Close to the business; fast access to information; no external fee Independence; specialist expertise; cross-market view; continuity if staff leave Builds internal capability; second pair of eyes before reports and inspections
Weaknesses Expertise and time may be thin; key-person risk Needs good data access and onboarding; quality varies by provider Costs two layers; responsibility must stay clearly with the appointed RC
Typical fit Group AIFMs with a compliance team; larger fund ranges Single-strategy funds, first-time managers, RAIFs and SCSps without in-house compliance AIFMs with a junior or newly appointed RC; transition periods
Board attention point Document the time allocated to the role and the RC's access to data Contract terms (named RC, replacement approval, written acknowledgement) Written scope and escalation rules

What should a board ask before appointing an RC?

  • Who exactly will be the RC, and who replaces them during absences?
  • How many mandates does this person hold, and how much time is allocated to our fund?
  • Can the RC show AML/CFT training and experience relevant to our strategy (VC, real estate, private debt)?
  • What access will the RC have to investor files, asset files and delegate systems, and from when?
  • What is the monitoring plan for year one, and what will we receive each quarter?
  • How will the RC escalate a suspicion, and is the RC registered on goAML?
  • Which tools will the RC use to keep evidence, and can we retrieve that evidence if the RC changes?

Selection criteria, pricing models and contract clauses are covered in choosing an outsourced RC.

Which RC pitfalls do supervisors and auditors find most often?

The recurring weaknesses are structural, not technical: an RC appointed on paper with no plan or evidence, a fund relying entirely on its AIFM's framework, asset due diligence missing on unlisted investments, and board minutes silent on AML/CFT.

What we observe most often when we take over an RC mandate or run a pre-inspection review:

  • The fund relies on the AIFM. No fund-level policy, no fund-level risk assessment, no fund RC report. The AED position is explicit: the AIFM's compliance never exempts the RAIF.
  • RR and RC collapsed into one person. A single director designated as RR and RC of a RAIF, which the AED does not allow.
  • No notification after a change. The RC changed, the board resolved it, but no updated Market Entry Form or AED RR/RC identification form was sent.
  • A template risk assessment. Scoring copied from another fund, with no link to the actual investor base, distribution channels or portfolio.
  • Asset due diligence treated as investment due diligence. Commercial and legal diligence exist; the AML/CFT screening of the target, seller and counterparties does not.
  • Delegate oversight reduced to collecting a policy. No sample outputs, no follow-up of the delegate's own audit findings.
  • Wrong deadline. Treating 31 May as the SRRC deadline for a fund whose year-end is not 31 December.
  • Unclear suspicion route. Delegates do not know whom to call; the RC is not registered on goAML.
  • Minutes that say nothing. "The board noted the RC report" is not evidence of oversight.

What are the sanctions and the current supervisory focus?

The recent published CSSF AML/CFT sanctions against fund managers target filing failures: a questionnaire not returned, an external report not filed. These are RC calendar items, and the RR is accountable for them.

The CSSF fined nine AIFMs EUR 10,000 each for failing to file the 2024 AML/CFT questionnaire (decisions of 11 September 2025, published 9 January 2026). In January 2024 it fined an AIFM EUR 10,000 and reprimanded three others for not filing the 21/788 external report.

The message for RCs is practical: sanctions hit first what is easiest to prove. A missed filing needs no qualitative judgement from the supervisor, which is why the reporting calendar deserves the same rigour as the controls behind it. On the AED side, reporting was extended to non-RAIF AIFs in February 2025, which brought many unregulated SCSps into a reporting cycle for the first time.

How RC Insight helps

RC Insight is the compliance operating system for Responsables du Contrôle. It centralises the RC's workflows across all mandates in one place:

  • Board-ready RC reports, built from the controls and evidence recorded during the year;
  • Document and policy expiry tracking, so KYC documents, policies and delegate reviews do not lapse unnoticed;
  • ML/TF/PF risk scoring across investors, assets and delegates, with a consistent methodology;
  • Delegate due diligence monitoring, from questionnaire to follow-up actions.

Request a demo (a short form, we reply within one business day) to see an RC's full annual cycle in the platform.

Frequently asked questions

What is a Responsable du Contrôle in Luxembourg?

The Responsable du Contrôle (RC) is the AML/CFT compliance officer that Luxembourg professionals, including investment funds and their managers, must appoint under Article 4(1) of the amended Law of 12 November 2004. The RC implements and tests the AML/CFT framework, escalates suspicions to the CRF and prepares the annual RC report or SRRC.

What is the difference between the RR and the RC?

The RR (Responsable du Respect des obligations) is accountable for AML/CFT compliance at management or board level. The RC (Responsable du Contrôle) is the compliance officer who implements and controls the framework day to day. Both are mandatory. In a RAIF, a single board member appointed as RR cannot also be the RC.

Can the RC be external to the fund?

Yes. The RC may be a board member, an employee of the AIFM or an external third party. For an external RC, the CSSF FAQ requires the contract to name the individual RC, to make any replacement subject to board approval and to be acknowledged in writing. The fund appoints a named person, not a firm.

Must a RAIF appoint its own RC if its AIFM already has one?

Yes. Every Luxembourg investment fund subject to AML/CFT supervision must appoint both an RR and an RC. The AED states that the AIFM's compliance never exempts a RAIF from its own AML/CFT obligations. The RAIF's board may designate an AIFM employee as RC, but it must appoint that person for the fund.

Who is the RR and RC of an SCSp?

An SCSp acts through its general partner, so the RR sits at that level: the general partner's board of managers acting collegially, or one of its managers. The general partner designates the RC. If the general partner is also the fund's registered AIFM, an RC is needed at both levels. An unregulated SCSp AIF is supervised by the AED.

How is the RC notified to the CSSF or the AED?

CSSF-supervised funds and IFMs notify their RR and RC through the AML/CFT Market Entry Form on eDesk at set-up, and changes must be communicated to the CSSF in advance. AED-supervised RAIFs and other AIFs use the AED RR/RC identification form, at first appointment and after any change.

What does the RC report annually?

CSSF-supervised entities file the SRRC under CSSF Circular 24/854, within five months after the closing of the annual accounts, exclusively via eDesk. RAIFs send the AED an annual RC report and AML/CFT questionnaire by 31 May, a date the AED confirms each year. In both cases the RC prepares the report and the RR remains accountable for it.

What changes with AMLR in 2027?

The EU AML Regulation 2024/1624 applies from 10 July 2027. Its Article 11 requires a management-body member responsible for AML/CFT and a compliance officer of sufficient standing, which broadly mirrors the RR/RC model. The roles remain, but the rulebook becomes a directly applicable EU regulation, and AMLA starts direct supervision of selected entities in 2028.

Sources