Luxembourg financial supervisor turns to APIs for AML reporting

Luxembourg financial supervisor turns to APIs for AML reporting

The article published a few weeks ago in Paperjam was clear: the Luxembourg financial supervisor becomes 4.0., “a real time supervisor”.1 In line therewith, the Commission de Surveillance du Secteur Financier (CSSF) has decided in its Circular n°20/7472 to impose, to certain supervised entities, the implementation of application programming interfaces (APIs) for AML reporting purposes. This choice is not trivial and raises the importance of implementing APIs for both supervised entities and regulators.

Reporting of IBAN accounts & safe deposit boxes

The above-mentioned Circular, adopted by the CSSF, is part of Luxembourg's AML V3 implementation.

As per Article 1(19) of AML V:

“Member States shall put in place centralised automated mechanisms, such as central registries or central electronic data retrieval systems, which allow the identification, in a timely manner, of any natural or legal persons holding or controlling payment accounts and bank accounts identified by IBAN […] and safe-deposit boxes held by a credit institution within their territory”.

These centralised automated mechanisms shall be set up by Member States by 10 September 2020.4

In its Law of 25 March 20205, the Luxembourg legislator made the choice of implementing a central electronic data retrieval system involving a remarkable novelty: the choice of a “pull” system.

From “push” to “pull”

Until now, most (if not all) of the reporting obligations involved the transmission of a file by the supervised entity to the CSSF. Such a transmission can be seen as a “push” from a file to the CSSF. On the contrary, the system established by the Law of 25 March 2020 involves rather6 a “pull” system, implying that the CSSF has “at any time an automated access to the data included in the data file”.7

This has been implemented as follows:

Source: CSSF Circular n°20/747, p.5. Free translation: “The CSSF central electronic data research system extracts the register upon a(n API) call of the professional. Irrespective of the professional’s availability, a research module will be put at the disposal of the national authorities.”

To implement this system, the CSSF imposes that the obliged entities:8

(i)  Consume the CSSF API for enrolment purposes,

(ii) Consume the CSSF API for data file availability notification purposes, and

(iii) Publish its own API for (a) retrieval of the full data file by the CSSF and (b) reception of the CSSF feedback regarding the status of the data file. 

Some may raise that this “pull” system is more complex to implement for both the supervised entities and the supervisor compared to the current standard reporting methods. This complexity is, however, counterbalanced by its benefits on the long run.

The use of APIs indeed enables both the obliged entities and the regulator to automate more easily the reporting process and create easier interactions with other applications. Even though it is not the case for the present reporting obligation, the CSSF could decide – for future obligations – that it would be sufficient for financial institutions to make APIs available to the CSSF through which the relevant data to be reported can be retrieved individually and on a need to know basis by the CSSF. This, however, would only be possible to the extent that such a method fulfils the requirements laid down but the European or Luxembourg legislator.

Such an approach would notably ease the processing of the reported data by the regulator. Currently, the CSSF and other supervisors receive a substantial amount of data that is difficult to analyse to as full an extent as possible. Adopting the “pull” system on a larger scale would solve this issue.

“According to the responses [to the Bafin report “Big data meets artificial intelligence”], analyses that are based on data that is gathered once or on a monthly/quarterly basis will increasingly lose relevance as the market becomes ever more dynamic. Supervisors should therefore seek to maintain real-time access to specific corporate data using application programming interfaces (APIs) and use this to conduct ongoing analyses, such as cash flow analyses, in order to identify new risks and business models at an early stage. Setting up APIs is also considered to be useful for a smooth exchange of data between different (supervisory) authorities. Making use of the interplay between APIs and BDAI would also allow supervisors to monitor outsourcing more effectively. This would mean that the relationships between the institutions involved could be taken into account in supervisory analyses automatically”.10

The benefits of implementing APIs for both supervisors and supervised entities are numerous, and the use of this technology will most probably soon become a must.

That being said, it is interesting to put this initiative of the CSSF in perspective with our neighboring countries

What about our neighbors?

As pointed out by the “Conseil d’Etat” in its commentaries, the Grand-Duchy of Luxembourg adopted a different approach than France and Belgium where a “push” system continues to be the rule.11

In France, an equivalent IBAN register as the one introduced by AML5 has actually already existed since 1982,12 under the name of “Ficoba”,13 (for purposes beyond the sole fight against money laundering)14 and has been lately updated to encompass additional information15. Obliged entities can transmit the information to the authority on an IT support, through a network or by way of sending a printed normalized form.16

In Belgium, a similar register as the French one (going beyond the sole AML purpose) called “Point de contact central des comptes et contrats financiers” has been introduced more recently, by way of a Law dated 8 July 201817. The data can solely be reported electronically18 by way of a channel defined by the National Bank of Belgium.19

Finally, Germany, already adopted a system in 2003 that is closer to the one chosen by the Luxembourgish legislator in the Law of 25 March 202020. Pursuant §24c (1) and (2) of the German Banking Act21, any credit institution shall have a file system containing certain data, which may be retrieved by the competent authority22. A difference with the Luxembourgish system, however, is that the credit institutions must keep the data file in a separate database to ensure the competent authority’s retrieval of information.23

Luxembourg, France, Belgium and Germany have - due to historical, social or economic reasons - technically implemented the same reporting obligation requirements differently. The choice of APIs for exchange of data by the Luxembourg regulator should nevertheless become the technical standard in Europe in order to ensure a smooth transition to a better and more effective reporting experience for both regulators and supervised entities.




