RC / AML-CFT Oversight

The Luxembourg RC: which funds need one and what does the role actually involve?

The role of Responsable du Contrôle, commonly referred to as the RC, has become one of the central components of AML/CFT governance for Luxembourg investment structures.

But appointing an RC is only the beginning.

The RC is expected to exercise genuine oversight over the fund’s AML/CFT framework, its investors, its investments and the parties to which AML activities have been delegated.

Luxembourg AML/CFT governance distinguishes between:

RR — Responsable du Respect des obligations

and

RC — Responsable du Contrôle du respect des obligations.

For investment funds and investment fund managers subject to CSSF AML/CFT supervision, the relevant framework requires the RR and RC functions. The AED applies the same governance principle within its own supervisory perimeter: every RAIF and every other AIF subject to AED AML/CFT supervision is required to appoint both an RR and an RC.

For a fund, the RR may be the governing body acting collectively or an individual member of that governing body.

The RC is appointed intuitu personae by the governing body and must have appropriate AML/CFT knowledge and experience. The RC may be a member of the board. If the board or other governing body acts collectively as RR, one of its members may also be appointed as RC. If, however, one individual member is appointed as the sole RR, that same person cannot also be the RC. In principle, the RC must be available in Luxembourg. An RC located outside Luxembourg can be accepted only in limited circumstances and subject to the applicable conditions – for example, where the relevant AIFM and the employee acting as RC are themselves not domiciled in Luxembourg. In all cases, the RC must understand the fund’s investment and distribution strategies, know the Luxembourg AML/CFT framework, remain available to the Luxembourg authorities and have access to the documents and systems necessary to perform the function.

The framework can apply across a broad range of Luxembourg investment structures.

This includes CSSF-supervised investment funds and investment fund managers, RAIFs supervised for AML/CFT purposes by the Administration de l’Enregistrement, des Domaines et de la TVA (AED), and other AIFs falling within the AED’s AML/CFT supervisory perimeter. Both AED categories require the appointment of an RR and an RC; what differs materially is the annual reporting and submission process.

The applicable reporting process nevertheless differs depending on whether the entity is supervised by the CSSF or AED.

This distinction is important.

The RC function should not be reduced to reviewing investor KYC files once a year.

An effective RC framework normally considers at least:

Investor-side AML

The fund should understand who its investors are, their beneficial owners, source of funds where appropriate, PEP status, sanctions exposure and risk profile.

High-risk relationships should be subject to enhanced due diligence and periodic reviews should be performed according to the risk classification.

Asset-side AML

AML obligations do not stop at the investor register.

The RC should also consider the fund’s underlying investments, including acquisition counterparties, target companies and other relevant parties.

Asset-side due diligence is not only a RAIF topic. The AED’s published RC-report expectations for both RAIFs and other AIFs expressly address due diligence performed on the assets of the fund. CSSF supervisory work also expects investment-fund managers to consider financial-crime exposure at asset level, including, where relevant, proliferation-financing risk.

Fund administrators, transfer agents, AIFMs and other providers may perform AML tasks.

Delegation does not mean that the fund should stop overseeing those activities.

The RC should understand:

  • what has been delegated;
  • who performs the controls;
  • how exceptions are escalated;
  • what overdue reviews exist;
  • whether AML procedures are actually being followed; and
  • whether the service provider’s performance remains consistent with both regulatory and contractual requirements.

The AED expressly includes oversight of delegated AML activities within its expected RC report content.

A fund should maintain documented risk assessments appropriate to its activities. Under the current AED RC-report expectations, money-laundering and terrorist-financing risks should be assessed separately. Sanctions and proliferation-financing (PF) exposure should also be considered and documented where relevant; CSSF supervisory work has specifically highlighted PF risk at asset level and identified a dedicated PF section within the risk assessment and AML/CFT policies and procedures as a good-practice approach.

Those assessments should consider the investor base, jurisdictions, distribution arrangements, investment strategy, underlying assets and target sectors, service providers, sanctions exposure, relevant PF indicators and other risk factors specific to the structure.

They should lead to an actual risk appetite and control framework rather than exist as static documents.

Delegating investor onboarding, screening or monitoring to an administrator or transfer agent does not mean that the fund can simply rely on that provider’s internal AML policy as if it were the fund’s own framework. The governing body remains responsible for ensuring that fund-specific AML/CFT policies, procedures and controls exist, reflect the fund’s risks and operating model, and are kept up to date. In practice, the RC will typically drive or coordinate the preparation and periodic review of that framework and test how it is implemented, with the governing body retaining responsibility for its approval.

An RC should perform risk-based testing rather than only read service-provider reports. This can include sampling investor files, checking whether the identification, beneficial-owner, source-of-funds or other required evidence has actually been provided to the transfer agent or administrator, reviewing the quality of periodic reviews, testing PEP and sanctions controls and following remediation. The RC should also be involved where an investor is blocked or restricted for AML/KYC reasons. In appropriate circumstances, the RC may provide a comfort letter or documented AML position to another service provider, but only where there is sufficient supporting evidence and without replacing that provider’s own regulatory responsibility.

Asset-side AML/KYC can create a practical gap before an investment committee approves a new transaction. This is particularly relevant for an authorised AIFM based outside Luxembourg that may have limited Luxembourg-specific AML knowledge, or for a registered AIFM or GP without a dedicated AML team. The required work may include identifying the target and relevant counterparties, understanding ownership and control, screening UBOs and key persons, considering sanctions, PEP and adverse-media results, assessing jurisdictional risk and documenting outstanding points for the investment committee. A specialist Luxembourg resource can support that workstream and prepare a clear due-diligence record while the investment decision remains with the AIFM and its investment committee.

Reporting requirements depend on the supervisory regime.

For CSSF-supervised entities within the scope of the AML/CFT Summary Report RC (the “SRRC”), the report is annual and is due within five months following the financial year-end.

For a 31 December year-end, that ordinarily points to 31 May.

For AED-supervised RAIFs, the filing process is campaign-driven and the AED website should be checked each year. For example, the 2026 campaign required the RC report and AML/CFT questionnaire covering 2025 to be submitted by 31 May 2026 – effectively five months after a 31 December year-end. That date should not be presented as an immutable annual rule: the scope, forms, submission mechanics and campaign instructions can change quickly.

For other AED-supervised AIFs, the 2026 submission of the 2025 RC report and AML/CFT questionnaire was by invitation from the AED. The absence of an invitation did not mean that the RC could skip the underlying annual controls, testing or documentation. The RC function still had to be performed and the annual work and report maintained so that they could be provided to the AED when requested or when an invitation was received.

This demonstrates why regulatory calendars should be reviewed each year rather than assuming that the previous year’s process remains unchanged.

The RC should not appear in April or May simply to prepare an annual report.

A more effective approach is to maintain an annual control plan covering matters such as:

investor reviews, asset-side due diligence, PEPs, sanctions, outstanding KYC, delegate oversight, AML training, suspicious activity, regulatory developments and implementation of previous findings.

The annual RC report should then become the conclusion of twelve months of oversight rather than an exercise in reconstructing the year after it has ended.

Weak AML/CFT governance can have immediate operational consequences: delayed investor onboarding, blocked subscriptions or distributions, transaction delays, audit findings, service-provider escalation and regulatory remediation. It can also lead to formal sanctions. Depending on the entity and the breach, the Luxembourg AML/CFT Law allows supervisory authorities to impose warnings, public statements, remedial orders and significant administrative fines. For certain professionals and breaches, statutory maxima can reach EUR 5,000,000 or 10% of annual turnover; obstruction of supervisory powers or failure to comply with certain supervisory requirements can itself attract fines from EUR 250 to EUR 250,000. Knowing breaches of specified AML/CFT duties may also carry criminal fines from EUR 12,500 to EUR 5,000,000. The applicable sanction always depends on the precise entity, obligation and facts.

Amana can act as RC or provide AML/CFT oversight support for Luxembourg investment structures, including fund-specific policy and risk-assessment work, risk-based testing of investor and asset files, oversight of delegates, follow-up of blocked-investor or remediation situations and annual RC reporting. Amana can also support AIFMs and GPs with Luxembourg-focused asset-side AML/KYC before investment-committee decisions, particularly where the manager is based outside Luxembourg or does not maintain a dedicated AML team. The focus is practical, documented and risk-based supervision throughout the year.

Topic

CSSF-supervised funds / IFMs

AED – RAIFs

AED – other AIFs

RR / RC

RR and RC functions required under the applicable CSSF framework.

Both RR and RC required.

Both RR and RC required.

RR / RC changes

Follow the applicable CSSF notification / approval process for the entity.

Identification form and signed appointment documentation to AED without delay on initial appointment or change.

Identification form and signed appointment documentation to AED without delay on initial appointment or change.

Annual RC report

SRRC, where in scope: within 5 months of financial year-end.

Annual AED campaign. For 2025 activity, deadline was 31 May 2026. Check the AED campaign each year.

RC work/report should still be performed. In 2026, submission of the 2025 report was by invitation.

Questionnaire / other annual filings

Separate CSSF annual AML/CFT questionnaires may have their own campaign deadlines.

AED AML/CFT questionnaire follows the annual RAIF campaign.

In 2026, questionnaire submission was by invitation.

Practical point: regulatory calendars, forms and campaign mechanics can change. The CSSF and AED websites should be checked before each filing cycle.