OSMIA CONSULTING OSMIA CONSULTING

AIFMD II & UCITS VI : Liquidity management tools

AIFMD II and UCITS VI are here — and while it does not overhaul the European framework, it introduces several important changes for asset managers and funds.

The revised directive strengthens, among other things, the liquidity risk management.

The two-LMT rule

All open-ended AIFs and UCITS are legally required to select and document at least two Liquidity Management Tools (LMTs) from a harmonised list of seven LMTs, such as swing pricing, redemption gates, anti-dilution levies, or side pockets.
The LMTs are divided into two categories: quantity-based and anti-dilution. It is recommended toapply at least one LMT from each category.

Disclosure

Fund documentation, including prospectuses and policies, must explicitly disclose the selected LMTs.

CSSF Reporting

The selected LMTs must be notified to the CSSF via eDesk.

What’s next

By 16 April 2027, more details must be provided on each LMT such as calculation methods and activation thresholds.
From 1 October 2027, stress testing and policies will strengthen LMT requirements.

Why the changes matter

The market is shifting from governance to evidence to ensure fair treatment of investors and financial stability.

How can Osmia Consulting help you?

With extensive experience in Luxembourg’s regulatory landscape, Osmia Consulting provides advisory and IT solut

At Osmia Consulting, we view regulation as a strategic enabler. When approached correctly, it strengthens organisations rather than constraining them.
Please get in touch to help you navigate the new requirements.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Benchmarking Compliance In 2026 : Insight Without Imitation

Benchmarking is widely used — and often misunderstood.

Best practices are not ready-made solutions. They are reference points, not blueprints.

Benchmarking Is Useful, and Dangerous

Benchmarking is often used to justify compliance choices.
Too often, it becomes a substitute for thinking.

What Regulators Expect

Frameworks must be:

  • Proportionate

  • Risk-based

  • Aligned with the institution’s actual operating model

Copying peers blindly creates misalignment.

Best Practices Are References, Not Templates

Strong compliance frameworks are designed, not replicated.

Benchmarking should inform judgement, not replace it.

How can Osmia Consulting help you ?

Osmia Consulting offers a tailor-made compliance gap analysis permitting the creation of your dedicated strong compliance framework, nothing more, nothing less.

In 2026, compliance excellence will be defined by intentional design, not imitation.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Delegation In 2026 : Oversight Cannot Be Outsourced

Delegation remains essential for efficiency and expertise.

Responsibility, however, always remains with the delegating entity.

Delegation Is Necessary, Responsibility Is Not Optional

Delegation allows institutions to access expertise and scale efficiently.
But responsibility, however, always remains with the delegating entity.

Regulatory Focus in 2026

Supervisors increasingly challenge:

  • Superficial oversight

  • Generic reporting

  • Lack of documented challenge

Passive monitoring is no longer acceptable.

What Effective Supervision Looks Like

  • Deep understanding of delegated activities

  • Continuous engagement

  • Evidence of challenge and escalation

Oversight must be both active and informed.

How can Osmia Consulting help you ?

With extensive expertise in due diligence methodologies, Osmia Consulting supports the design and implementation of delegate oversight through data analysis, reporting frameworks and governance structures

Delegation frameworks fail when oversight becomes symbolic.
Now is the time to strengthen control over your delegation framework.

Read More
OSMIA CONSULTING OSMIA CONSULTING

ESG Compliance In 2026 : From Narrative to Evidence

ESG is no longer a communication topic. It is a compliance discipline.

ESG Has Entered the Compliance Sphere

ESG is no longer about intentions or communication. It is about verifiable, controlled and consistent information.
By 2026, ESG disclosures will be subject to increasing regulatory scrutiny.

Where the Real Risk Lies

The main ESG risk today is not non-compliance.
It lies in inconsistencies between:

  • What is disclosed

  • What is measured

  • What is controlled

Greenwashing is often the result of weak governance, not bad faith.

What Robust ESG Compliance Requires

  • Clear methodologies

  • Reliable data

  • Controls comparable to financial reporting

ESG requires the same discipline as any regulatory domain.

How can Osmia Consulting help you ?

Osmia Consulting goes beyond consultancy and advisory services. It also provides IT solutions to structure data, strengthen data controls and avoid inconsistencies.

If ESG matters, it must be governable, auditable, and defensible.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Compliance Culture In 2026 : Beyond Policies and Procedures

Policies, procedures and controls are essential. But they do not operate themselves.

In 2026, regulators increasingly assess how people behave, not just what documents say.

Rules Do Not Enforce Themselves

Institutions often invest heavily in policies and controls.
Yet failures still occur, not because rules were missing, but because people did not act.

What Regulators Look for Today

Supervisors increasingly assess:

  • Awareness of responsibilities

  • Escalation behaviour

  • Practical understanding of risk

Culture is no longer implicit.
It is examined.

What Strong Compliance Culture Looks Like

A strong compliance culture is not about fear.
It is about:

  • Clarity

  • Accountability

  • Empowerment

It enables people to act correctly in ambiguous situations.

How can Osmia Consulting help you ?

Osmia Consulting has developed strong governance mechanisms in order to ensure escalation, actions and effective solutions. Our experience is at your disposal.

Technology supports compliance, processes structure it and culture determines whether it works.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Data Governance In 2026 : The Silent Backbone of Compliance

Most compliance failures do not originate in legal interpretation.

They originate in inconsistent, incomplete or poorly governed data.

Most Compliance Failures Are Data Failures

Rarely do compliance issues arise from missing rules. They arise from poor, inconsistent or poorly governed data. In 2026, supervisors increasingly focus on the reliability of data underpinning compliance decisions.

What Data Governance Really Means

Regulatory expectations now include:

  • Clear data ownership and accountability

  • Consistency across reports and controls

  • Full traceability from source to decision

Data governance is no longer an IT concern.
It is a governance and compliance imperative.

The Cost of Weak Data Foundations

Without strong data governance:

  • Controls lose credibility

  • Reporting becomes fragile

  • Management decisions are undermined

Compliance cannot be stronger than the data supporting it.

How can Osmia Consulting help you ?

Thanks to our IT and operational teams, Osmia Consulting has developed tailor-made solutions to manage data effectively.

In 2026, compliance frameworks will stand or fall on data discipline.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Operational Resilience : Built in Daily Operations, Not in Crisis Mode

Operational resilience is often discussed through extreme scenarios: cyber-attacks, system outages, market shocks.

But regulators know the truth: resilience is built — or weakened — in everyday operations.

Resilience Is Tested Long Before Disruption

Operational resilience is often discussed in extreme scenarios.
In reality, it is shaped by everyday decisions. Regulators know this, and increasingly assess resilience as an organzational capability, not a contingency document.

What Supervisors Expect in 2026

Expectations now include:

  • Clear identification of critical activities

  • Mapping of operational dependencies

  • Ability to continue services under stress, not just recover afterwards

Resilience cuts across compliance, risk, IT, outsourcing, and governance.

Where Institutions Struggle

Most weaknesses stem from:

  • Fragmented responsibilities

  • Poor understanding of operational interdependencies

  • Lack of realistic testing

Resilience fails quietly until it doesn’t.

How can Osmia Consulting help you ?

With extensive experience in financial sector operations, Osmia Consulting conducts gap analysis to map internal dependencies.
Combined with its IT experience, Osmia delivers IT tools and solutions to strengthen your operational resilience and your organizational capability.

It is about being structurally prepared before pressure arises.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Compliance Automation in 2026 : When Speed Meets Responsibility

Automation is no longer a differentiator. By 2026, it has become a baseline expectation.

Yet, many institutions confuse automation with control. Digitising a process does not automatically make it compliant — and in some cases, it can amplify weaknesses.

Automation Has Become the Baseline

By 2026, compliance automation is no longer innovative, it is expected.
Yet, many institutions still confuse automation with control.
Digitizing a weak process does not make it compliant.
It often causes its weaknesses to spread faster.

The Hidden Risks of Poorly Governed Automation

Supervisors increasingly question:

  • Who owns automated controls?

  • How thresholds, alerts and exceptions are defined

  • How human judgement intervenes when automation fails

The risk is not technology, it is technology operating outside governance.

What “Good” Automation Looks Like

Effective compliance automation should:

  • Enhance traceability and auditability

  • Improve consistency across controls

  • Support decision-making rather than replace it

Automation must serve governance, not bypass it.

How can Osmia Consulting help you ?

With extensive experience in regulatory automation, Osmia Consulting offers IT solutions that enable automation without losing control.

In 2026, the real challenge is not automating more. It is automating responsibly, explainably and sustainably.
Compliance technology without governance is not progress. It is deferred risk.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Regulatory In 2026 : From Compliance Burden to Strategic Advantage

For many financial institutions, regulation is still approached as a constraint — something to absorb, interpret, and survive.

But 2026 confirms a structural shift: regulation is increasingly shaping how institutions are organised, governed and managed.

Regulation Is No Longer Peripheral, It Is Structural

For years, regulation has been treated as an external constraint: something to interpret, implement, and report on.
In 2026, this perception is no longer sustainable.
Supervisors across Europe are shifting their focus. The question is no longer whether policies exist, but how regulation is embedded into the organization’s operating model.

What Regulators Really Assess Today

In practice, regulatory reviews increasingly focus on:

  • How responsibilities are exercised, not just documented

  • How governance bodies challenge and decide

  • How risks are identified, escalated, and tracked over time

Static compliance frameworks are giving way to expectations of dynamic, demonstrable control.

Regulation as a Structuring Force

Institutions that integrate regulatory requirements into their governance, processes, and decision-making gain more than compliance:

  • Clearer accountability

  • Better internal alignment

  • Stronger resilience under supervisory scrutiny

Those that do not often find themselves constantly reacting.

How can Osmia Consulting help you ?

With extensive experience in Luxembourg’s regulatory landscape, Osmia Consulting provides regulatory advisory and IT solutions to address compliance challenges and strengthen corporate governance.

At Osmia Consulting, we see regulation as a strategic structuring tool. When approached correctly, it strengthens organizations rather than constraining them.
In 2026, regulation will either shape your institution, or continuously disrupt it.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Regulatory Retrospective 2025: A Transformative Year for the EU Financial Sector

2025 was a decisive year for EU financial regulation — from CRR3/CRD6 implementation to ESG refinement, digital resilience focus and the first wave of regulatory simplification initiatives.

Osmia Consulting looks back at the key developments that shaped the year and outlines what institutions should prepare for as we head into 2026.

The year 2025 marked a genuine turning point for EU financial regulation. Reforms advanced across prudential supervision, sustainable finance, digital resilience and market infrastructure, creating a fast-moving environment that required institutions to adjust quickly and thoughtfully.

Highlights of 2025

  • CRR3/CRD6 implementation brought stronger capital requirements, clearer risk management expectations and reinforced governance standards.

  • Digital resilience came into sharper focus, with DORA preparation intensifying and supervisors paying closer attention to third-party ICT dependencies.

  • Sustainable finance frameworks continued to mature, including refinements to the EU Taxonomy and evolving ESG disclosure requirements.

  • Supervisory convergence progressed, with ESAs working more closely to address cross-border issues and reduce fragmented expectations.

  • Administrative burden reviews signalled early steps toward simpler, more proportionate reporting and transparency obligations.

What This Means for 2026

As institutions move into 2026, they will face a mix of simplification measures, updated supervisory expectations and evolving sustainability criteria. Staying ahead will require solid governance, strong internal alignment and a clear understanding of regulatory priorities for the year ahead.

Osmia's Perspective

At Osmia Consulting, we see 2025 as having laid the foundations for a more coherent and proportionate regulatory landscape.
Our focus is on helping clients interpret these developments, adapt efficiently and maintain strong, reliable compliance frameworks.

Let Osmia help you navigate these developments. Contact us to find out how we can support your compliance needs.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Regulatory Simplification 2026: What Financial Institutions Should Expect

Regulatory simplification is becoming a major theme for 2026. From benchmark rules to reporting obligations and securitisation transparency, the EU is recalibrating the compliance landscape to reduce administrative burden while maintaining supervisory integrity.

In our new publication, Osmia Consulting explores what these simplifications mean in practice — and how firms can benefit from them without increasing regulatory risk.

Throughout 2025, the European Commission intensified its efforts to simplify regulatory obligations and reduce unnecessary administrative burdens across the financial sector. These initiatives aim to improve competitiveness and operational efficiency while maintaining strong supervisory outcomes.

With several simplification measures expected to take effect from early 2026, financial institutions will need to reassess their internal controls, reporting frameworks, and compliance processes.

Key Areas of Simplification

  • Reporting Obligations – Greater alignment and consolidation of templates across prudential, supervisory, and sustainability-related frameworks, reducing duplicated submissions.

  • Securitization Transparency – More proportionate disclosure expectations for simple structures and revised information flows for investors.

  • Supervisory Coordination – Enhanced cooperation between ESAs to limit inconsistent requests and improve predictability for supervised entities.

Opportunities and Considerations

While administrative burdens may ease, institutions must remain vigilant to ensure their interpretations remain aligned with supervisory expectations. Simplification does not reduce accountability; prudential, operational, and conduct-related risks remain central to supervisory priorities.

How can Osmia Consulting help you ?

Osmia Consulting helps institutions redesign their compliance and reporting frameworks to benefit from regulatory simplification, combining efficiency with robust controls to ensure traceability and consistency. We assist clients by mapping revised obligations, adapting internal processes, strengthening governance and documentation, and ensuring alignment with supervisory expectations.

Please feel free to contact us for a comprehensive compliance assessment.

Read More
OSMIA CONSULTING OSMIA CONSULTING

EU Sustainable Finance in 2026: What to Expect from the Evolving EU Taxonomy

The EU Taxonomy is set for further refinement in 2026, with updated criteria, clarified DNSH expectations and stronger alignment with CSRD.

These changes will reshape how institutions classify activities, report sustainability information and design ESG-aligned products. In our latest insight, Osmia Consulting outlines what organisations should expect — and how to prepare effectively.

As 2026 approaches, the EU’s sustainable finance framework is moving into a new phase of consolidation. In recent years, the EU Taxonomy has expanded its scope, refined its technical screening criteria and clarified the application of the “Do No Significant Harm” (DNSH) principle.

With new delegated acts currently being prepared, supervised entities should expect both opportunities and challenges as they update their strategies, data processes and disclosures.

Key Evolutions Expected for 2026

  • Updated technical screening criteria, incorporating sector feedback and aiming for greater usability.

  • Clearer DNSH guidance, improving comparability and reducing interpretative uncertainty.

  • Potential new environmental objectives, broadening the scope of sustainability-linked disclosures.

  • Further alignment of reporting templates, supporting interoperability with CSRD and ESRS requirements.

Impact for Market Participants

Financial institutions and asset managers will need to reassess product governance, client disclosures and eligibility assessments. Corporates will need to update data collection processes, integrate revised criteria into sustainability planning and anticipate increasing investor scrutiny.

How can Osmia Consulting help you ?

Osmia Consulting supports institutions in implementing sustainable finance obligations through practical, operational and regulatory expertise. Our approach focuses on proportionality, efficiency and the real needs of your compliance function, helping you navigate evolving Taxonomy requirements with confidence.

If you would like to discuss how we can support your sustainable finance and Taxonomy compliance needs, please feel free to contact us.

Read More
OSMIA CONSULTING OSMIA CONSULTING

The EU Artificial Intelligence Act

Artificial intelligence is reshaping the financial industry — but with innovation comes regulation.

The EU Artificial Intelligence Act is the world’s first framework setting clear rules for trustworthy and responsible AI.

For financial institutions, the real question is: how can you stay compliant while still innovating with confidence?

The AI Act has become a reality

As the world’s first comprehensive AI regulation, the EU Artificial Intelligence (AI) Act introduces a risk-based framework to ensure that AI is trustworthy, transparent, and safe.

Implication for the financial sector

For the financial sector, the implications are significant:

  • High-risk AI Systems – such as credit scoring, automated compliance tools and risk assessment models - will be subject to strict obligations, including transparency, human oversight, and robust risk management.

  • Governance and documentation will be central: firms must maintain detailed records and demonstrate how their AI tools meet regulatory standards.

  • Accountability will fall on both developers and deployers of AI solutions.

How can Osmia Consulting help you ?

At Osmia Consulting, we are uniquely positioned to help clients navigate these new requirements. Our consultants provide guidance on compliance strategies and governance frameworks, while our IT officers design tailored solutions to ensure your AI tools meet regulatory expectations.

Whether you are developing internal tools or deploying external solutions, Osmia helps you align innovation with compliance.

Get in touch to discuss how we can build a tailored compliance roadmap for your AI journey under the EU AI Act.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Independent Directors: Brief analysis

In Luxembourg, Directors play a central role in shaping strategy, safeguarding governance, and ensuring compliance. But beyond legal requirements, Independent Directors bring something more: objectivity, expertise, and the ability to balance competing interests in a transparent and professional manner.

At Osmia Consulting, we believe that independent oversight is not just a regulatory box to tick – it is a driver of trust, resilience, and long-term success.

Why should I appoint Directors?

If we take the example of a very common corporate form, the limited company, having a Board of Directors is a legal requirement. The Law of 10 August 1915 on Commercial Companies states that companies in Luxembourg can be structured as single-tier entities or as two-tier entities. In the first case, the company must have a Board of Directors with at least three members. The Board of directors can delegate certain responsibilities to a Management Board. Two-tier structures have, in addition to the Executive Board (Directoire), a Supervisory Board.

What are the responsibilities of a Director?

In Luxembourg, the Board of Directors of a public limited company (Société Anonyme) for example, is primarily responsible for the corporate governance of the company. However, shareholders may also have the power to resolve certain matters that are reserved for them by law or the company’s articles of association. Such matters include, among others, the appointment and dismissal of the Directors, the approval of accounts, the granting of discharge, the appointment of the auditor, the amendment of the company’s articles of association as well as decisions regarding capital increases or decreases, mergers, divisions or the company’s liquidation.

The Board of Directors and Supervisory Board is the main organ responsible for shaping the company’s strategy.
The primary responsibilities of Directors are as follows :

  • to manage the company with a level of diligence and prudence (“en bon père de famille”) with a best efforts approach and without any obligation to meet a specific outcome;

  • to ensure that the interests of the company prevail over their personal interests, and to avoid any conflicts of interest;

  • to ensure that they have and maintain the necessary skills, qualities and time capacity to fulfil their duties, and to avoid disclosing any confidential information.

What are the liabilities of a Director?

With regards to liability, the members of the management body can be held accountable for their actions in the following ways :

  • towards the company if they commit an error that damages it;

  • towards the company or third parties if their conduct is in breach of the applicable law and/or the articles of association. In this case, shareholders may individually act against the Directors or members of the management committee if they prove that they were independently prejudiced;

Is the Director required to be independent?

According to the ALFI’s Code of Conduct for Luxembourg Investment Funds:

“The Board should have good professional standing and appropriate experience and ensure that it is collectively competent to fulfil its responsibilities.”

“Consideration should be given to the inclusion in the Board of one or more members that are, in the opinion of the Board, independent.”

Whilst Luxembourg company law makes no distinction between types of Directors (and therefore all Directors have the same duties and responsibilities), corporate governance practice tends to divide Directors into different groups, usually as follows:

  • Director - any member of a Board of Directors of a company

  • Executive Director – a Director who is also an employee of the company (and in the context of Funds, usually taken to include any persons employed within the promoter group)

  • Non-Executive Director (“NED”) – a Director who is not an Executive Director

  • Independent Non-Executive Director (“iNEDs”) – a NED who is also considered Independent

It is for the Board to adopt the appropriate criteria for the assessment of the independence of its Directors.
However some criteria have been established by the market. Indeed, such criteria are set out in more detail in Appendix D of the X Principles of the Luxembourg Stock Exchange.
Additionally, ILA specifies that “Conflicts of interest may arise from many different situations and relationships, including, for example economic interests, relationships or prior employment, but “Consideration also has to be given to personal relationships, […] it is very relevant in a country such Luxembourg, given the proximity of families, business partners and service providers.”

What is the added value of the Independent Director?

Independent Non-Executive Directors bring significant added values to a Luxembourg structure, particularly in regulated and investment-oriented entities such as funds, SPVs, and corporates.

Among those, the main ones are:

  • objectivity,

  • enhanced governance,

  • Luxembourg regulation compliance,

  • conflict of interest mitigation,

  • sharing of expertise, industry knowledge and best practices and

  • networks.

Independent Non-Executive Directors bring significant added-values to a Luxembourg structure, particularly in regulated and investment-oriented entities such as funds, SPVs, and corporates. Among those, the main ones are objectivity, enhanced governance, Luxembourg regulation compliance, conflict of interest mitigation and sharing of expertise, industry knowledge, best practices and networks.

How can Osmia Consulting help you ?

With proven expertise in governance and regulatory matters, Osmia Consulting provides experience and truly independent Directors for funds, SPVs, and corporates. Our profiles combine strong industry knowledge, objectivity, and hands-on experience to bring real value to your Board.

Choosing Osmia means embracing independence, integrity, and impact.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Delegation and Supervision: Are You Truly Able to Supervise Your Delegates?

Delegation has become a cornerstone of Luxembourg’s financial and corporate ecosystem. Portfolio management, distribution, central administration - almost everything can be delegated. But one thing never is: responsibility.

The CSSF has been clear - delegation does not remove the duty to supervise. And yet, in practice, effective oversight remains the exception rather than the rule. Too often, monitoring is passive, responsibilities are unclear, and evidence of actual supervision is missing.

In Luxembourg’s financial and corporate landscape, delegation has become the norm: portfolio management, distribution, central administration … Almost everything can be delegated - everything - except responsibility.

The CSSF keeps repeating it: the delegation does not remove your duty to supervise. Yet, in practice, supervision is still too often the exception. At Osmia Consulting, we help stakeholders turn this regulatory obligation into a true governance asset, strengthening one of the most critical pillars of long-term success.

What the CSSF Really Expects

  • Due diligence
    A thorough preliminary review of delegates, including initial due diligence, assessment of specific risks, and approval by the relevant governing bodies.

  • Contracts
    A clear contractual framework defining access rights, reporting commitments, and transparencyobligations.

  • Monitoring
    A documented monitoring system, including the analysis of periodic reports, formalized meetings, and systematic follow-up on corrective actions.

Common Weaknesses

  • Passive or absence of monitoring
    Receiving a report is not supervision. The report must be reviewed, questioned, and followed by concrete action.

  • Vague roles and responsibilities
    Who supervises what? The Board, the RR, the RC? Too many structures lack a clear allocation of responsibilities.

  • Lack of concrete evidence
    The CSSF is not only interested in what is done, but in what can be demonstrated and documented.

How to Strengthen Supervision

  • Formalize monitoring committees, with agendas, minutes, and clear action plans.

  • Define key indicators - such as KPIs, incidents, and contractual compliance - tailored to each type of delegation.

  • Act proactively: don’t wait for the annual report to respond. Implement alerts, hold quarterly meetings, and conduct targeted site visits when necessary.

Supervision is not about ticking boxes. It requires an active, critical, and ongoing approach.
Osmia Consulting helps its clients shift from a model of blind trust to one of enlightened, proportionate, and demonstrable supervision.

How can Osmia Consulting help you?

We combine deep regulatory expertise with hands-on experience.
Working in close partnership with our clients, we tailor practical, effective solutions that are fully aligned with CSSF expectations - and that work in practice, not just on paper.


Partner with Osmia Consulting to elevate your governance so your board can focus on what matters most: steering the organization toward long-term success. Contact us to find out how we can support your governance needs.

Read More
OSMIA CONSULTING OSMIA CONSULTING

Automating Compliance in 2025

Automation is everywhere in compliance agendas in 2025 - but is it always the right answer?

Regulatory complexity has reached a level where manual processes are no longer sustainable. Yet, with the proliferation of “miracle tools” and one-size-fits-all solutions, firms risk either over-investing in technology or relying on tools that fail to address their real needs.

Promises, Limits, and Best Practices

"Automation" is everywhere in every compliance agenda in 2025. And for good reason: regulatory complexity has reach a level where manual management is no longer viable.

However, with so many “miracle” tools and poorly adapted solutions on the market, it can be difficult to identify what truly fits your needs. At Osmia Consulting, we believe automation should empower and enhance your control framework, never replace your professional expertise.

The Promises of Automation
Automation brings genuine benefits, including:

  • Greater efficiency in compliance controls

  • Fewer human errors and more reliable audit trails

  • Enhanced traceability and auditability

  • Reduced long-term operating costs

  • Improved resource allocation - freeing teams from repetitive tasks to focus on higher value added activities

The Limits of Automation

However, automation is not a cure-all, it:

  • Requires significant initial and ongoing investment

  • Demands strong change management and buy-in from your teams

  • Necessitates ongoing adaptation of processes and documentation

  • Carries the risk of excessive reliance on technology, sometimes at the expense of regulatory understanding

Best Practices Observed Among Our Clients

  • Begin with a thorough assessment of existing processes before automating: what are the real pain points?

  • Choose modular, scalable tools, that are appropriate for the organization’s size and regulatory obligations.

  • Involve control functions early in the configuration process, to avoid building unnecessary bureaucracy.

  • Support change management with clear updated procedures and targeted team training.

How can Osmia Consulting help you ?

With extensive experience in Luxembourg’s regulatory landscape, we offer deep compliance expertise, ensuring efficient and expert management of your compliance requirements. By working together with IT specialists, we enable our customers to take their compliance controls to the next level through automation.

Automation is not an end in itself. When thoughtfully implemented, it allows control functions to become strategic again-focusing on analysis rather than just data gathering. That’s the approach Osmia Consulting promotes, with simple, practical solutions that are truly adopted by teams.

Read More
OSMIA CONSULTING OSMIA CONSULTING

CSSF 18/698 : 5 erreurs encore trop fréquentes en 2025

Depuis son entrée en vigueur, la Circulaire CSSF 18/698 constitue une pierre angulaire du cadre réglementaire luxembourgeois en matière de gestion d’actifs. Pourtant, en 2025, nous observons encore des erreurs récurrentes qui pourraient facilement être évitées.

Depuis qu’elle a été appliquée, la Circulaire CSSF 18/698 est devenue une référence incontournable dans la gestion des sociétés de gestion d’actifs au Grand-Duché du Luxembourg.

Pourtant, en 2025, certains problèmes récurrents persistent. En tant que société de conseil travaillant sur le terrain, Osmia Consulting identifie régulièrement les mêmes lacunes, qui pourraient souvent être évitées.

1. Confusion des fonctions de contrôle
Les rôles de MLRO, RR et RC sont parfois mal compris ou mal attribués. Une même personne peut cumuler plusieurs fonctions, mais cela suppose une rigueur dans la formalisation des responsabilités, la disponibilité et la compétence. Trop de structures ignorent encore les seuils d’incompatibilité prévus par la réglementation.

2. Documentation de gouvernance insuffisante
Les politiques existent, mais leur mise à jour est négligée. Plus préoccupant encore : certaines ne sont pas pleinement approuvées par le Conseil d’administration ou ne reflètent pas fidèlement l’activité réelle. La CSSF sanctionne désormais ces manquements, même en l’absence de mauvaise foi, conformément à ses exigences en matière de gouvernance.

3. Supervision insuffisante des délégataires
La supervision des fonctions déléguées (notamment en matière de gestion ou de distribution) est souvent réduite à une formalité administrative. Or, une délégation ne dispense jamais de la responsabilité légale et réglementaire. L'absence de rapports formels ou de KPI clairement définis constitue un indicateur de risque majeur qui doit être traité en conséquence.

4. Revues de conformité trop génériques
Une revue annuelle fondée sur un modèle générique ne permet pas de répondre aux exigences d’une approche véritablement fondée sur les risques. La CSSF attend une analyse ciblée, proportionnée à l'activité réelle de la société et intégrant ses risques inhérents.

5. Manque de déclenchement d’une revue externe en temps opportun
Le recours à une revue externe du dispositif de contrôle n’est pas toujours considéré avec le sérieux requis, même lorsque les circonstances l’imposent. Pourtant, cet exercice constitue un levier essentiel pour renforcer la crédibilité et la robustesse de l’organisation.

Comment Osmia Consulting peut-elle vous aider ?

Forte d'une vaste expérience dans le paysage réglementaire luxembourgeois, Osmia Consulting met à votre disposition un vivier diversifié de professionnels qui peuvent agir en tant que RC, administrateur indépendant ou consultant de votre entreprise, garantissant ainsi une gestion experte et efficace de vos obligations de conformité.

Faites de la conformité un levier de professionnalisation plutôt qu’un simple exercice défensif.
Osmia Consulting accompagne ses clients dans cette démarche, en mettant l’accent sur la proportionnalité, la traçabilité et l’efficacité.

Read More
OSMIA CONSULTING OSMIA CONSULTING

The Future of Financial Regulation in the EU

At Osmia Consulting, we believe the regulatory landscape is undergoing a quiet but powerful transformation. In our latest article, "The Future of Financial Regulation in the EU", we explore the key trends shaping the next decade — from digital compliance and supervisory convergence to ESG accountability and governance.

Whether you're a compliance professional, legal advisor, or policy watcher, we invite you to read our perspective and join the conversation.

Three trends to watch

As we approach mid-2025, EU financial regulation is entering a new phase : more integrated, more digital, and more demanding. At Osmia Consulting, we’re keeping a close eye on the shifts that will shape the compliance landscape for years to come.

Here are three regulatory trends we believe will have the biggest impact on Luxembourg’s financial sector:

1. Digital Operational Resilience Act (DORA) : From Framework to Enforcement
DORA is no longer a theoretical framework : it is now an operational reality. Firms must now demonstrate not only cyber resilience but also robust ICT third-party risk management.

Regulatory scrutiny will move from paper policies to real, tested digital resilience.

2. ESG: From Voluntary to Verified
With the Corporate Sustainability Reporting Directive (CSRD) and European Sustainability Reporting Standards (ESRS) taking hold, ESG is shifting from aspirational to accountable. Firms will require robust internal control frameworks, validated data, and clearly traceable audit trails to meet regulatory expectations.

3. Supervisory convergence in the EU
The European Supervisory Authorities (ESAs) are increasingly harmonizing supervision across Member States. For Luxembourg firms, this means local compliance must now align with a more coordinated EU-wide standard. National specificities still matter, but pan-European consistency has become the new benchmark.

What are the implications for compliance officers, legal teams, and executive management?

Greater cross-functional collaboration. Increased automation. A more strategic approach to compliance.
At Osmia, we believe that anticipating these trends - rather than merely reacting to them - is essential to achieving sustainable compliance and effective risk management.

How can Osmia Consulting Help you ?

With extensive experience in Luxembourg’s regulatory landscape, Osmia Consulting offers advice and support, ensuring efficiency and expert handling of your compliance requirements.

We’d be delighted to discuss how your firm can turn regulatory change into a competitive advantage.

Read More
OSMIA CONSULTING OSMIA CONSULTING

OSMIA x Le Figaro

Sandra Lucente, Managing Partner and co-founder of Osmia Consulting, shared during an exclusive interview with Le Figaro, on the company’s activities and ongoing journey to adapt and thrive in the ever-changing governance, compliance and project management solutions they provide for the financial sector.

During the interview, Sandra Lucente shared insights into OSMIA Consulting’s areas of expertise whilst highlighting the company’s dynamic approach in navigating the evolving financial landscape. The interview emphasises OSMIA’s commitment to continuous innovation and adaptation, ensuring it remains at the forefront of the ever-changing financial sector.

Watch the full interview to find out more:

Read More
OSMIA CONSULTING OSMIA CONSULTING

CSSF Circular 18/698

In Luxembourg’s evolving regulatory landscape, the annual review under CSSF Circular 18/698 is more than a box-ticking exercise - it’s a vital opportunity for investment firms and other financial sector professionals to reinforce their compliance framework.

Whether you’re refining your monitoring plan, aligning policies with the latest regulations, or enhancing governance practices, this guide is designed to support your efforts.

A Practical Checklist for Compliance Officers

As the regulatory landscape continues to evolve, the annual review required under CSSF Circular 18/698 remains a cornerstone of the compliance function for all investment firms, UCIs, and other professionals of the financial sector (PSFs) in Luxembourg. Yet, for many compliance officers, navigating this process can feel like a maze - especially when balancing operational responsibilities with strategic oversight.

Here's a practical checklist to guide your annual review and help ensure that your compliance framework remains both robust and adaptive.

Governance and role clarity

  • Confirm that responsibilities and reporting lines of the Compliance Function are documented and up to date.

  • Review and update the mandate of the Compliance Officer (“Responsable du Contrôle de la Conformité”).

  • Ensure that the independence and effectiveness of the Compliance Function are preserved and clearly demonstrated.

Review of internal policies and procedures

  • Reassess key policies (e.g. AML/KYC, Market Abuse, Conflicts of Interest, MiFID) for relevance and completeness.

  • Ensure procedures reflect recent regulatory updates and any changes to the business model.

  • Cross-check alignment with other functions (e.g. Risk, Internal Audit, Legal).

Risk-based monitoring activities

  • Document all compliance controls carried out during the year.

  • Identify any gaps or weaknesses, along with the corresponding remediation actions.

  • Assess the adequacy of risk scoring methodologies applied to clients and services.

Reporting and escalation

  • Confirm that internal reporting to senior management and the Board occurred in a timely and comprehensive manner.

  • Ensure all regulatory filings and notifications were submitted correctly and on time.

  • Record any incidents, breaches, or alerts, including how they were resolved.

Staff training and awareness

  • Review attendance records and the content of compliance training delivered.

  • Identify the needs for refreshers or thematic training.

  • Confirm that outsourced staff and third-party service providers received adequate compliance orientation.

Follow-up on CSSF communications and circulars

  • Verify that all CSSF circulars, newsletters, and FAQs from the past year have been reviewed and assessed for impact.

  • Implement or schedule any necessary updates to internal policies or procedures.

Action plan for the coming year

  • Draught a compliance monitoring plan for the upcoming year, using insights from this review.

  • Prioritize high-risk areas and upcoming regulatory developments (e.g. DORA, CSRD, AML package).

  • Set SMART objectives and define measurable KPIs for the Compliance Function.

How can Osmia Consulting help you ?

At Osmia Consulting, we work closely with compliance professionals to ensure these obligations are not only met, but transformed into value-added processes.

The annual review is not just a regulatory formality - it’s a strategic opportunity to strengthen your compliance culture, anticipate regulatory risks, and demonstrate governance maturity.

Read More