CDD audit checklist and assessment guide
This guide provides Luxembourg compliance teams and audit professionals with a practical AML file quality scoring methodology covering assessment criteria, regulatory expectations, scoring templates, and common deficiencies. You’ll learn how to evaluate CDD file completeness and accuracy against CSSF standards, implement consistent file quality processes, and audit AML documentation for regulatory readiness.
Introduction
Luxembourg-regulated entities (investment fund managers, asset managers, and financial services providers) must maintain AML compliance documentation that meets Commission de Surveillance du Secteur Financier (CSSF) expectations.
However, documentation completeness alone doesn’t satisfy regulatory requirements. CSSF onsite inspections and independent testing examine whether CDD files contain verified customer information, complete beneficial ownership identification, documented risk assessments, source of funds verification, and evidence of ongoing monitoring. A structured AML file quality scoring methodology helps compliance teams and auditors assess file completeness, identify remediation gaps early, and meet CSSF examination readiness standards.
File quality scoring is a systematic, post-execution quality assurance (QA) function: once customers are onboarded and CDD is collected, file quality scoring for Luxembourg entities evaluates whether documentation meets defined standards. Luxembourg entities face particular complexity given the international investor base in the fund sector, cross-border asset structures, and multi-layered ownership arrangements. CSSF Regulation No. 12-02 requires risk-based due diligence, and CSSF guidance (updated December 2024) clarifies expectations for both listed and unlisted asset documentation.
What is AML file quality scoring in Luxembourg?
AML file quality scoring is a systematic review process that evaluates the completeness, accuracy, and regulatory compliance of CDD documentation maintained in customer files. The objective is to assess whether each CDD file contains required information (identity, beneficial ownership, and risk factors), supporting evidence (verification documents, screening results, and risk assessment notes), and ongoing monitoring records.
File quality scoring differs from customer risk categorization. Risk categorization (high, medium, low) determines the depth of due diligence required; file quality scoring audits whether due diligence was actually performed and documented to that standard. A customer rated low-risk should have a proportionately streamlined but complete file. A customer rated high-risk should have enhanced due diligence documentation with robust evidence of wealth/source verification and regular ongoing monitoring updates.
In the Luxembourg context, file quality scoring addresses CSSF expectations: entities must be able to demonstrate that CDD was performed, documented, and periodically refreshed. CSSF inspections request customer files; inadequate documentation results in findings and potential enforcement action.
Why does file quality scoring matter for Luxembourg entities?
Common file quality gaps in Luxembourg inspections include incomplete customer identification (missing address or contact details), weak beneficial ownership identification (unclear who ultimate beneficial owners are), missing source of funds documentation (no verification of where investor capital originated), inadequate risk assessment notes (file shows a risk rating but no documented rationale), incomplete screening evidence (unclear what lists were checked or when), and weak ongoing monitoring records (periodic reviews not documented with update dates).
Aside from regulatory risk, poor file quality creates operational challenges. When compliance teams cannot quickly locate required documentation, responding to CSSF information requests becomes lengthy and error-prone. If files lack clear risk assessment reasoning, re-rating investors during periodic reviews becomes inconsistent. Cross-border fund operations depend on reliable due diligence documentation; if files are weak, service providers and counterparties may decline the relationship. Investors become inconsistent during periodic reviews. Cross-border fund operations depend on reliable due diligence documentation; if files are weak, service providers and counterparties may decline the relationship.
CSSF regulatory framework and file quality expectations
Luxembourg AML/CFT requirements are set out in the Law of 12 November 2004 (amended) and CSSF Regulation No. 12-02 of 14 December 2012. Key articles require the following:
Article 14 et seq.: Institutions must establish customer due diligence procedures, identify customers and beneficial owners, and verify identity using reliable documentation.
Article 34(2): Asset due diligence obligations; professionals must assess money laundering and terrorist financing risks and perform due diligence proportionate to the assessed risk.
CSSF Circular 25/878 (adopted January 2025): Guidance on ML/TF risk factors; entities should reference these in risk assessments and file documentation.
CSSF FAQ (December 2024): Clarifies asset due diligence expectations for listed and unlisted assets, frequency of documentation updates, and risk assessment renewal requirements.
EU AML Directive/Regulation: Luxembourg entities must also align with EU framework expectations, including sanctions screening, beneficial ownership transparency, and politically exposed person (PEP) checks.
CSSF supervisory expectation: CDD files must contain documented evidence of due diligence performed, risk assessment conclusions, and ongoing monitoring activity. Files should be audit-ready; an external auditor or CSSF inspector should be able to review the file and verify compliance.
AML file quality scoring methodology for Luxembourg
Use this step-by-step process to assess file quality:
Step 1: Define scoring criteria
Establish a scoring framework specific to your entity’s risk profile and product type. Typical criteria include customer identification (complete, verified); beneficial ownership (identified, verified); risk assessment (documented, supported by evidence); screening (list of vendor/date, results documented); source of funds (for high-risk, verified); ongoing monitoring (periodic update dates, review notes); and file organization (all documents located and indexed).
Step 2: Develop a scoring template
Create a template assigning point values to each criterion. Example: Customer identification (25 points), beneficial ownership (25 points), risk assessment (20 points), screening (15 points), source of funds (10 points), ongoing monitoring (5 points). Total score: 100 points.
Step 3: Select and audit a sample
Choose a representative sample of customer files (stratified by risk category and product). Audit each file against your scoring template.
Step 4: Document findings
Record deficiencies, remediation actions, and responsible parties. Identify root causes (process gaps, training gaps, system gaps).
Step 5: Track remediation
Assign owners and deadlines. Verify completion. Update aggregate file quality metrics quarterly.
Step 6: Report and iterate
Report file quality metrics to compliance leadership and the board. Adjust scoring criteria annually based on CSSF guidance updates and internal learnings.
AML file quality scoring template
Use this checklist to evaluate individual CDD files:
| File quality element | Criterion | Score | Comments |
|---|---|---|---|
| Customer identification | Full name, date of birth, address (current and verified) | 0-25 | Missing any element = deduction |
| Document verification | Identity document type, issue/expiry dates, copy in file | 0-15 | Document outdated or copy illegible = gap |
| Beneficial ownership | UBO identified, percentage ownership documented, declaration signed | 0-25 | Missing declaration or unclear ownership chain = deficiency |
| UBO verification | Company registration or trust deed obtained and reviewed | 0-10 | For entities only; missing = major gap |
| Risk assessment | Risk level assigned, factors documented, review date noted | 0-20 | Generic comments or missing rationale = weakness |
| Sanctions screening | Vendor name, screening date, results documented | 0-15 | Missing vendor or date = gap; unclear results = issue |
| Source of funds (high-risk) | Documentation of source, verification performed, notes in file | 0-10 | High-risk investor without source doc = major deficiency |
| Ongoing monitoring | Periodic review dates logged, file updated with findings | 0-5 | Missing update dates = compliance gap |
| File organization | All documents indexed, easily located, no duplicates | 0-10 | Scattered documentation = assessment friction |
| Audit trail | Who completed CDD, when, and any changes logged | 0-5 | Missing metadata = audit trail weakness |
| Total | 0-100 |
Scoring interpretation: 90-100: Compliant; 75-89: Minor gaps (document, remediate); 60-74: Significant gaps (remediate within 30 days); below 60: Material deficiencies (escalate, senior review required).
Common file quality deficiencies
Typical gaps found in Luxembourg entity audits include:
Incomplete identification: The customer file is missing the current address, contact phone, or second address despite entry into the fund (common when the investor updates contact details post-onboarding but the CDD file is not updated).
Weak beneficial ownership identification: File shows company name and investor details but lacks identification of actual beneficial owners, ownership percentages, or trust beneficiaries.
Missing source of funds verification: For high-risk investors (PEPs, high-risk jurisdictions, and complex structures), the file lacks documentation of how the investor acquired capital or a third-party reference.
Risk assessment not documented: The investor was assigned a risk level, but no notes in the file explain why or reference CSSF risk factors.
Screening evidence incomplete: File notes the screening vendor but lacks date, result, or alert disposition. It’s unclear whether the investor was re-screened during the holding period.
No ongoing monitoring record: File created at onboarding but has no notation of periodic reviews, re-screening activity, or relationship refreshes.
Document quality issues: Verification documents are photocopies of poor quality, illegible, or outdated (expiry dates exceeded).
Inconsistent ownership documentation: For entity investors, the file lacks a company registration extract, memorandum of association, or trust deed confirming ownership structure.
Best practices for file quality
Documentation Standard: Maintain a consistent standard for all customer tiers. High-risk files should have substantially more evidence; low-risk files can be streamlined but not absent.
Periodic Review Schedule: Establish a calendar-based periodic review process. High-risk: annual. Medium-risk: biennial. Low-risk: every 3–5 years. Update files with review dates and any risk reassessment.
Screening Evidence Trail: Record screening activity in the file: vendor, date screened, screening tool version, results, and any alert investigation and disposition.
Risk Assessment Documentation: When assigning risk, document the reasoning (e.g., “High-risk: PEP + high-risk jurisdiction + complex UBO structure requiring EDD”).
Beneficial Ownership Certification: Obtain signed beneficial ownership declarations from entity customers. Update every 2 years or when the structure changes.
File Organization: Use consistent naming, indexing, and storage. Make files easy to retrieve during CSSF requests or audits.
Training and Ownership: Ensure operations and compliance staff understand file quality standards. Assign clear ownership for file updates.
Technology for AML file quality management
Manual file audits using spreadsheets are time-consuming and error-prone. Platforms supporting AML file management can streamline quality assurance:
Automated scoring can apply your quality criteria to customer files and flag gaps for remediation. Workflow management routes periodic review tasks and tracks completion dates. Document storage centralizes CDD files, verification documents, and screening evidence in searchable, indexed repositories. Audit trails record who updated files, when, and what changed, supporting regulatory demonstrations of control. Periodic review scheduling automates calendar-based review assignments and sends reminders to assigned owners.
FAQs
How often should we perform file quality audits?
A baseline audit of high-risk customer files is recommended at least annually. For all customer files, consider a biennial comprehensive review. After remediation activities, validate that corrections were applied to files and that quality gaps do not recur.
What if we find a file quality deficiency during a CSSF inspection?
Document the deficiency, develop a remediation plan with timelines, and provide progress updates to the CSSF per its supervisory expectations. Deficiencies should be escalated to your compliance officer and board. Close remediation activities with evidence of corrected files and controls implemented to prevent future occurrences.
What is Cascade, and how does it help with AML compliance?
Cascade is a workflow management platform designed to help compliance teams operationalize their AML controls library. Cascade automates customer screening, centralizes due diligence documentation, manages periodic review workflows, consolidates screening alerts, and maintains complete audit trails of compliance activities. This reduces manual effort, improves consistency, and provides the documented evidence that regulators examine during inspections.
What data sources does Cascade integrate with for customer screening?
Cascade integrates with leading screening data providers, including LSEG World-Check, Dow Jones Risk & Compliance, and Acuris Risk Intelligence. These integrations enable automated screening of customers and beneficial owners against global sanctions lists, PEP databases, and watch lists. Cascade consolidates results from multiple sources, flags alerts for review, and maintains audit logs of all screening activities.
Explore Cascade’s AML compliance capabilities for Luxembourg
Maintaining file quality across a large customer base is operationally challenging when relying on manual processes and spreadsheets. CSSF examination findings increasingly cite incomplete or unorganized CDD files as compliance gaps, triggering remediation requirements and supervisory attention.
Cascade helps Luxembourg-regulated businesses streamline AML compliance workflows across onboarding, screening, alert handling, reporting, and analytics.
Its AML Software (SaaS Platform) supports more efficient, consistent compliance processes aligned with Luxembourg’s regulatory environment.
Explore Cascade’s compliance workflow capabilities →
Disclaimer
This article is for general information only and is not legal, regulatory, or compliance advice. AML requirements, file quality standards, and regulatory expectations vary by entity type and jurisdiction (Luxembourg and beyond) and evolve continuously. The regulatory information and CSSF guidance reflect publicly available sources as of the publication date but may not reflect recent rule changes, enforcement priorities, or your specific regulatory context.
This article does not establish a lawyer-client or compliance consultant relationship. Before implementing specific file quality methodologies, interpreting CSSF expectations, or making material compliance decisions, consult with qualified legal counsel, your compliance officer, and your regulator (CSSF or other supervisory authority).
Cascade is a workflow platform and does not provide legal or compliance advice. Use of Cascade does not guarantee compliance with any regulation or law. Errors and omissions may exist in this article; Cascade is not liable for their use or consequences.






































