ALCO
AML/CFT oversight
that goes beyond
the annual review.
I am Katia Ciesielska, a Luxembourg independent non-executive director. I hold AML/CFT accountability as RC or RR on regulated Luxembourg entities. Board-level AML/CFT accountability, RC and RR capacity, and independent oversight for Luxembourg regulated entities — from SIFs and RAIFs to PSFs and AIFMs.
RC and RR are not interchangeable.
Under CSSF Regulation 12-02, the two roles carry different accountability. Most boards conflate them. The distinction determines where liability actually sits.
The compliance function: monitors, controls and reports. Responsible for the AML/CFT programme itself — policies, screening, transaction monitoring, CSSF reporting, STRs to the CRF (Luxembourg’s FIU). Can sit outside the board, but must have direct access to it.
The board-level accountable person: signs off on the AML/CFT framework, is answerable to the CSSF for the entity’s compliance, and signs off on the annual AML/CFT compliance report to the board. Must be a member of the governing body. This is where the primary accountability to the CSSF sits.
I hold both roles across current mandates — RC and RR on separate entities, including CSSF-supervised PSFs and SIF/RAIF structures.
Board-level accountability.
Independent compliance oversight.
Credentials that hold up under scrutiny.
CSSF engagement,
not just reporting.
AML/CFT work in Luxembourg means direct supervisory engagement — authorisations, thematic reviews, inspections, remediation. I have experience across all of them.
The model generates
the alert. The RR is
still responsible.
AI is already embedded in the services Luxembourg fund boards delegate. Screening, transaction monitoring, administrator workflows — the board’s AML/CFT oversight obligation does not stop at the delegate boundary.
AI GOVERNANCE FOR BOARDS →Your administrator’s screening system is almost certainly AI-assisted. Under the EU AI Act, transparency obligations have applied since 2 August 2026. Your delegate knows. The question is whether your board does.
An RR who cannot say whether AI is embedded in the entity’s AML programme — or what oversight arrangements govern it — has a gap in their accountability. The EU AI Act does not suspend AML/CFT obligations while a delegate’s model is under review.
The question I ask of every delegate as part of AML/CFT board oversight: “What AI is embedded in the services you deliver to us — and how are the EU AI Act obligations allocated between us?” Most delegates have not been asked.
What is the difference between an RC and an RR, and why does it matter?
Under CSSF Regulation 12-02, the RC is the compliance function: the person who runs and monitors the AML/CFT programme. The RR is the board member who carries ultimate accountability — who certifies the annual AML report and is personally answerable to the CSSF. The RC can sit outside the board; the RR cannot. Many boards and promoters conflate the two, which creates a governance gap that the CSSF increasingly focuses on in inspections. The practical consequence is that having both clearly appointed — and both understanding their separate obligations — is a precondition for sound AML/CFT governance, not an administrative detail.
Is the RC the same as an MLRO?
Not exactly. Luxembourg splits into two designations what common-law jurisdictions — the UK, Ireland, the Channel Islands, the US — bundle into a single MLRO. The RC monitors and runs the AML/CFT programme day to day. The RR is the board member who is personally answerable to the CSSF. The two roles together cover what a single MLRO does elsewhere, but they carry different accountability and can be held by different people — which is the point.
Can the RC function be outsourced? Can the RR?
The RC function can be outsourced to a third party — compliance firms and ManCos do this routinely. The RR cannot be outsourced. The RR must be a member of the governing body of the regulated entity: a director, a manager, a gérant. That is the asymmetry that matters. An external compliance firm can run your AML/CFT programme; it cannot be your RR. That role requires someone with a seat at the table and a personal accountability to the CSSF.
What does the annual AML/CFT summary report involve, and who submits it?
Under Article 42(7) of CSSF Regulation 12-02, the RC prepares the annual AML/CFT summary report — covering the entity’s risk profile, the controls in place, any deficiencies identified, and the remediation taken. The RR submits it to the CSSF, via eDesk, and stands behind it personally. The report is one of the primary documents a CSSF inspector reviews. A board that has never read it, or cannot say when it was last submitted, has a gap.
What should a board expect of its AML/CFT director?
More than approving the annual AML report. A board-level AML/CFT director should be able to read and challenge the ML/TF risk assessment, ask substantive questions about the entity’s exposure to high-risk jurisdictions, PEPs and complex structures, understand whether delegate oversight arrangements are adequate, and assess whether the entity is actually prepared for CSSF scrutiny. In Luxembourg, the CSSF has been explicit in its guidance that board responsibility for AML/CFT is not satisfied by receipt of management reports alone. The director must engage.
Need RC or RR capacity on a regulated entity?
For board-level AML/CFT mandates, RC or RR appointments, or governance advisory on AML/CFT risk, contact me directly.
KATIA@KATIACIESIELSKA.COM →