Assess the risks of an outsourcing arrangement under Circular CSSF 22/806 (as amended by Circular CSSF 25/883), points 66–70, with sub-point answers and the contractual safeguards check (points 83–87 and 101). Companion to the Criticality Assessment (points 15–20): its point 20 screen asks for this tool's outcome.
These fields populate the memo header and the register field 55(c). Point 31 note: this assessment applies to all arrangements with third parties, whether or not they are outsourcing.
The circular's footnote points in particular to entities in scope of Article 59-3 LFS — the provision under which the CSSF, after consulting the BCL, designates other systemically important institutions (O-SII) and sets their capital buffers. Practical test: is the entity on the CSSF's current O-SII list? A handful of large Luxembourg banks are; specialised and support PFS are not.
Step-in risk is the risk of having to support a service provider in financial distress — financially, or by taking over its business operations — beyond any contractual obligation, typically under reputational or operational pressure. It matters at systemic scale, which is why the circular targets it at significant entities. If unsure, confirm the entity's classification with compliance; answer Yes only if the entity is actually designated.
Complete the selections above to continue.
Rate each dimension's inherent risk, answer the sub-points, record the mitigating measures (point 69(d)), then the residual rating. A residual below inherent needs the mitigation text to justify the movement.
Scale : 1 Low — no material concern · 2 Moderate — manageable within existing controls · 3 High — material exposure needing dedicated mitigation · 4 Severe — could threaten continuity, compliance or client outcomes.
Rate every dimension, answer every sub-point and safeguard, and justify any residual below inherent with mitigation text.
Edit freely, then paste into your register (or the IddiLabs Outsourcing Register). Also enter the residual tier in the Criticality Assessment's point 20 screen.
| Item | Anchor |
|---|
Trace each requirement — including every lettered and numbered sub-point — to where it was answered, and see honestly what sits outside this tool.
| Point | Requirement (paraphrased) | Status · where |
|---|
The AI extract is a self-describing copy of the whole assessment: every dimension, sub-point, safeguard status, rating and mitigation, plus the computation rules and caveats — ready to paste into Claude, Copilot or any model, or to archive. The JSON version embeds the raw state, so Load working file re-imports it later for the periodic update; Markdown is the paste-into-a-chat version. Data-classification note: pasting the extract into an external AI transfers the data to that provider.
Enter the residual tier in the Criticality Assessment (point 20 screen) · run the Due Diligence (points 71–75) on the provider · check the full contract with the Contract Clause Gap Checker · log the arrangement in the Outsourcing Register.