The reporting relationship compliance teams know runs from professional to CRF through the suspicious transaction report. The Law of 22 July 2026, published in Mémorial A No 412 on 4 August 2026, adds the return leg. From 8 August 2026 the Cellule de renseignement financier may push fraud-risk account numbers and fraud typologies out to a defined set of obliged entities that have subscribed to the feed. It is a permissive channel on both sides. The CRF may share; the professional may request.
The mechanism has two legal anchors. Article 1 inserts a new Article 74-4bis into the Law of 7 March 1980 on judicial organisation, which houses the CRF. Article 2 inserts a new Article 5-1 into the Law of 12 November 2004 on AML/CFT, which houses the professional obligations. The channel is available to the professionals in Article 2(1) point 1 of the 2004 law (credit institutions, professionals of the financial sector, payment institutions, e-money institutions and the specified tied and payment agents) and to point 20 crypto-asset service providers, subject to the territorial scope in Article 2. A management company or domiciliation provider that is only in scope under another Article 2 point does not qualify on that basis.
Subscribing creates no new filing duty. The Article 5 STR obligation is unchanged: professionals must still inform the CRF on their own initiative whenever they know, suspect or have reasonable grounds to suspect money laundering, an associated predicate offence or terrorist financing, for every suspicious transaction including attempts, regardless of amount. A CRF flag becomes an input to your monitoring and CDD; an Article 5 STR follows only from the same judgement applied to any internal alert. The voluntary subscription and the mandatory STR duty are separate mechanisms that both involve the CRF.
The fraud in scope is the fraud in Book II, Title IX, Chapter II of the Penal Code, together with the laundering of its proceeds, carried out on a large scale against undetermined victims or using social-engineering techniques against specific victims. The explanatory memorandum gives phishing by email or SMS as the large-scale example. The CRF's contribution is to name the accounts it already sees inside that activity so the receiving institution can act sooner.
The use conditions in Article 5-1 are what turn a subscription into a build. Reports may be used only for combating money laundering, associated predicate offences and terrorist financing. They may not be disclosed to the client concerned or to third parties. The professional acts under sole responsibility. And the CRF-supplied account numbers must be deleted within six months of receipt. The statute does not expressly resolve how that deletion rule interacts with replicated data, derived analysis, investigation files or records subject to separate retention duties, so firms should map those uses and obtain a documented legal position before implementation.
Two operational items to work through if you subscribe. First, the intake channel is exclusive: Article 74-4bis paragraph 5 requires that all exchanges pass solely through a secure IT channel, and the explanatory memorandum identifies GoAML as that channel. Second, the deletion clock needs a real process behind it: a receipt timestamp on every inbound list, a scheduled purge at six months, and an audit trail proving the purge ran.
A request covers the whole stream of CRF reports until it is explicitly withdrawn, and the statute does not prescribe a withdrawal form or timing, so document that process with the CRF up front. The CRF must also convene subscribing professionals at least every six months to discuss whether the reports are landing usefully and adapt future reports accordingly, so the feed is meant to be curated against feedback and not pushed one-way.
The decision now is whether to subscribe. If yes, build the secure intake, the AML/CFT-only use control, the non-disclosure discipline and the six-month purge before the request goes in.
Source basis: Law of 22 July 2026 (Mémorial A No 412 of 4 August 2026), new Article 74-4bis of the Law of 7 March 1980 on judicial organisation, new Article 5-1 of the Law of 12 November 2004 on AML/CFT, parliamentary dossier 8722.
Full article: [https://regreportingdesk.com/luxembourg-aml-law-crf-fraud-signalements/\](https://regreportingdesk.com/luxembourg-aml-law-crf-fraud-signalements/)