IddiLabs · Outsourcing & ICT Risk · Browser-only — nothing is stored or sent

Outsourcing Risk Assessment

Assess the risks of an outsourcing arrangement under Circular CSSF 22/806 (as amended by Circular CSSF 25/883), points 66–70, with sub-point answers and the contractual safeguards check (points 83–87 and 101). Companion to the Criticality Assessment (points 15–20): its point 20 screen asks for this tool's outcome.

Arrangement details

These fields populate the memo header and the register field 55(c). Point 31 note: this assessment applies to all arrangements with third parties, whether or not they are outsourcing.

Criticality determination of the function pt 67 · pt 20
From the companion Criticality Assessment. If critical, important or still pending, a high-severity scenario is required in D1.
Proportionality pt 67 · pt 4
Small entities may run this qualitatively; others should inform the scenario analysis with loss data where available.
Is the entity a significant entity? pt 69(c)
What "significant" means here — and what step-in risk is

The circular's footnote points in particular to entities in scope of Article 59-3 LFS — the provision under which the CSSF, after consulting the BCL, designates other systemically important institutions (O-SII) and sets their capital buffers. Practical test: is the entity on the CSSF's current O-SII list? A handful of large Luxembourg banks are; specialised and support PFS are not.

Step-in risk is the risk of having to support a service provider in financial distress — financially, or by taking over its business operations — beyond any contractual obligation, typically under reputational or operational pressure. It matters at systemic scale, which is why the circular targets it at significant entities. If unsure, confirm the entity's classification with compliance; answer Yes only if the entity is actually designated.

Is the provider a group entity? pt 12
Is the service a pure ICT service? pt 1(6) · pt 115

Complete the selections above to continue.

Eleven dimensions — points 66 to 70

Rate each dimension's inherent risk, answer the sub-points, record the mitigating measures (point 69(d)), then the residual rating. A residual below inherent needs the mitigation text to justify the movement.

Scale overlay: 1 Low — no material concern · 2 Moderate — manageable within existing controls · 3 High — material exposure needing dedicated mitigation · 4 Severe — could threaten continuity, compliance or client outcomes.

Rate every dimension, answer every sub-point and safeguard, and justify any residual below inherent with mitigation text.

Outcome · Circular CSSF 22/806, points 66–70

How this outcome is computed — reperformance note

Next scheduled update of this risk assessment pt 106 · pt 104 overlay

Register-ready value pt 55(c)

Edit freely, then paste into your register (or the IddiLabs Outsourcing Register). Also enter the residual tier in the Criticality Assessment's point 20 screen.

What this assessment feeds — and what it doesn't

ItemAnchor

Reconciliation map — point per point

Trace each requirement — including every lettered and numbered sub-point — to where it was answered, and see honestly what sits outside this tool.

PointRequirement (paraphrased)Status · where

Portable record — for your own AI tools and future updates

The AI extract is a self-describing copy of the whole assessment: every dimension, sub-point, safeguard status, rating and mitigation, plus the computation rules and caveats — ready to paste into Claude, Copilot or any model, or to archive. The JSON version embeds the raw state, so Load working file re-imports it later for the periodic update; Markdown is the paste-into-a-chat version. Data-classification note: pasting the extract into an external AI transfers the data to that provider.

Next steps in the tool chain

Enter the residual tier in the Criticality Assessment (point 20 screen) · run the Due Diligence (points 71–75) on the provider · check the full contract with the Contract Clause Gap Checker · log the arrangement in the Outsourcing Register.