Last updated

How to Verify a Luxembourg Adviser or Private Bank in CSSF Records

To verify a Luxembourg adviser, investment firm, private bank, payment provider, fund manager, or other financial-sector firm, start with the exact legal entity and the official CSSF Search Entities tool. A CSSF record can help confirm that an entity appears in a supervisory or registration framework, but it is not the same as proof that a salesperson is genuine, a product is suitable, a website is authentic, or a payment beneficiary is safe. The useful decision path is to match four boundaries at once: the legal entity, the authorised or registered activity, the communication route, and any CSSF or foreign-authority warning tied to the same name, domain or impersonation pattern.

This guide answers the practical query behind "how to verify a Luxembourg financial advisor is CSSF registered" and "how to verify a private bank is regulated by CSSF," while keeping the wording precise. It is written for consumers, investors, founders, family offices, job movers, and anyone checking a Luxembourg financial offer before sending money, identity documents, account statements, crypto, or investment instructions.

Direct answer

Use the CSSF register as the official starting point, not as the whole decision. The CSSF help page explains that a public database of entities supervised by the CSSF is available through Search Entities; its mission page describes the CSSF as the supervisory authority of the Luxembourg financial sector; and its warnings and financial-fraud pages explain why readers must still check warnings, cloned websites, unsolicited offers, domain names, contact details and payment requests. Record the result as evidence of what the official source showed on the date checked, not as a CSSF endorsement of the offer.

QuestionPractical answerEvidence to keep
Is the firm in the CSSF register?Search the exact legal name, not just a brand, product, app, adviser name, or website slogan.Register result, legal name, category, address, source URL and check date.
Is the offered service covered?Compare the entity type and activity with the actual offer: private banking, investment advice, portfolio management, payment service, fund management, credit, crypto-asset service, or another regulated activity.Offer documents, activity description, register category and notes on any mismatch.
Is it a private bank?Check whether the legal entity is a credit institution or relevant branch, and whether the contact route actually belongs to that institution.CSSF Search Entities result, independent website/contact page, email domain, phone number and payment beneficiary.
Is it an individual adviser?Do not assume a salesperson is personally authorised because a firm appears in Search Entities. Verify the employing or contracting firm and ask for written confirmation through official channels.Name of person, firm reply from official contact route, role, date and service scope.
Is it passporting from another EU country?A provider may rely on a home-state authorisation or branch/free-services route. Verify both the Luxembourg-facing record and the home regulator record when the CSSF result is not enough.CSSF record, foreign regulator record, passport or branch indication, and source-check date.

Step 1: identify the exact legal name

The most important control is boring: write down the exact legal entity. Fraud and confusion often hide behind a brand name, trading style, website, "group" label, individual adviser name, or translated name. A real Luxembourg private bank or investment firm should be able to give its legal name, legal form, registered address, registration identifiers where relevant, and the entity that will contract with you.

Do not search only the name in the logo. Search every variation you have: legal name, former name, product name, domain, app name, adviser name, email domain, IBAN beneficiary, and any company number. If the offer document says one name but the transfer beneficiary says another, treat that as a live mismatch until explained in writing.

Step 2: search CSSF Search Entities yourself

Open the official CSSF tool directly: CSSF Search Entities. Do not rely only on screenshots, certificates, downloaded PDFs, or links sent by a salesperson. Use the register to confirm the legal name, category, status indicators, address and the relevant activity labels shown by the official tool.

The CSSF help page says Search Entities is available to all users for entities supervised by the CSSF. That matters because the task is independent verification: you are confirming information at the source, not trusting a document that may have been altered.

Step 3: compare activity scope with the offer

A register hit does not mean every service sold under a similar name is covered. Match the status to the specific service. Credit institutions are different from investment firms, payment institutions, e-money institutions, investment fund managers, funds, auditors, support PFS, specialised PFS, credit servicers, crowdfunding service providers, crypto-asset service providers, and branches.

Offer you receivedRegister questionWhy the distinction matters
Private banking, deposit account or lendingIs the contracting entity a credit institution or relevant branch?Private banking branding is not the same as a bank licence, and wealth products may be provided through several group entities.
Investment advice or portfolio managementWhich firm provides the investment service, and is that service in scope?The individual adviser may be a representative, employee, tied intermediary or unauthorised impersonator.
Payment account, card, e-money or transfer serviceIs the provider a payment institution, e-money institution, bank or passporting provider?Money movement and safeguarding questions depend on the legal provider.
Fund, SICAV, UCITS, AIF or management companyAre you checking the fund, the manager, the depositary, the distributor, or a fake clone?Each role answers a different trust question.
Crypto exchange, token or recovery serviceIs the provider within a CSSF-supervised crypto-asset or AML/CFT perimeter, or merely using Luxembourg language?CSSF fraud guidance specifically warns about crypto-related fraud and recovery-fee scams.

Step 4: check warnings and fraud patterns

Search the CSSF warnings database and read the CSSF warnings information page. The CSSF explains that warning lists are intended to alert the public to potential fraud or illegal activity by service providers or individuals without required authorisations, and that the lists are not exhaustive. In practice, no warning found does not equal "safe."

Also read CSSF financial fraud guidance. It highlights unsolicited contact, supposed quality labels or authorisation certificates, high returns, time pressure, foreign payment routes, unclear products, incomplete documents, cloned websites, and the misuse of real supervised entities as warning signs. These checks are especially important when someone claims to be a Luxembourg private banker, investment adviser, CSSF agent, recovery specialist, or wealth manager.

Step 5: verify domain, contact route and payment beneficiary

Fraud often uses a real firm's name but a false communication route. Compare the domain in the email, the domain in the web address, the phone number, the postal address, the app, the bank account beneficiary, and the person asking for payment. A similar domain is not enough. A foreign number for a Luxembourg entity can be a warning sign. A payment beneficiary that differs from the regulated entity can be a stop signal.

If the CSSF record or official firm website gives a contact channel, use that channel. Ask whether the person, domain, offer, account beneficiary and product are genuinely connected to the firm. Preserve the reply. If you only receive voice messages or messages from a free email account, do not treat that as verification.

Adviser versus firm: what you can and cannot prove

Many user searches ask whether a "financial adviser" is CSSF registered. The safer question is: which legal firm is responsible for the advice, what activity is being provided, and is the person contacting you authorised by that firm to act in that capacity? A firm record may prove the firm appears in a public framework, but it does not automatically prove every individual using the firm's name is genuine or that the advice is suitable.

Ask for the adviser's full name, role, employer or contracting entity, professional email, telephone number, supervisory status of the firm, and the written client agreement. Then verify through the official firm route, not the contact details supplied in the suspicious conversation.

Private bank checks

For a private bank, focus on legal identity, bank status, group structure, service entity, custody route, deposit product, investment service, and client agreement. A group may include a bank, investment firm, management company, fund, insurance intermediary, custodian, or foreign branch. Your task is to identify which entity takes your money, which entity gives advice, which entity holds assets, and which entity signs the contract.

The CSSF credit institutions page explains that credit institutions receive deposits or other repayable funds from the public and grant credits for their own account, and that they are legally authorised to exercise activities regulated by the Luxembourg financial-sector law, including investment services. That statement does not mean every private banking offer is safe or suitable. It means the register and activity scope are the first controls before product due diligence.

EU passporting and cross-border providers

Some providers serve Luxembourg through a branch or free provision of services from another EU or EEA country. If Search Entities or a provider document suggests passporting, identify the home regulator and verify the home-state record too. Passporting is not a marketing label; it is a legal route tied to a specific entity, activity and jurisdiction. If the offer points to a foreign firm, compare the foreign register, Luxembourg-facing disclosure, contact route and contractual entity.

False positives and limits of a CSSF register check

A register entry can still leave important questions open. It may not prove a current employee is genuine, that a product is suitable, that a document is authentic, that a payment beneficiary is correct, that a foreign group entity is covered, or that a cloned website is harmless. It also may not answer whether you have a complaint, compensation, tax, inheritance, AML/CFT, sanctions, or private-law issue.

Use precise language in your notes. "The legal entity appears in CSSF Search Entities on July 18, 2026, under the category shown in the register" is stronger and safer than "CSSF approved this investment." A public register supports identity and status checking; it does not replace financial advice, legal advice, product risk review, or fraud investigation.

Evidence file to retain

  1. Exact legal name, brand name, adviser name and claimed group name.
  2. CSSF Search Entities result with date checked and category shown.
  3. Home regulator result if the provider claims EU passporting or foreign authorisation.
  4. Warnings database search for legal name, brand, domain, individual names and payment beneficiary.
  5. Offer documents, client agreement, fee schedule, risk warnings and product description.
  6. Domain, email headers, phone numbers, contact page and independent firm reply.
  7. Payment details: beneficiary, IBAN, wallet, country, reason for transfer and invoice.
  8. Chronology of calls, chats, emails, remote-access requests and pressure tactics.

Complaints and escalation

If you are already a customer of a professional under CSSF supervision, the CSSF customer complaints page explains that the CSSF can receive complaints from customers of professionals subject to its supervision and act as an intermediary for amicable settlement. The page also describes filing routes and supporting documents. It is not a shortcut for every fraud or contract dispute, and it does not replace police, bank, legal or court action where those are the appropriate route.

If the problem is suspected fraud before a relationship exists, start by preserving evidence, contacting your bank or payment provider where money moved, searching warnings, and contacting the real firm through independent details if its identity was misused. If identity documents, remote access, crypto wallets or passwords were involved, treat the matter as urgent account-security work as well as a regulatory verification issue.

Official source baseline

Bottom line

Do not stop at "CSSF registered." Verify the legal entity, authorised or registered activity, person, domain, payment route, warnings and contract. If those pieces do not line up, pause before sending money or documents and build a dated evidence file.