EMEA | Financial services

CSSF - Circular 17/654

The Commission de Surveillance du Secteur Financier (“CSSF”) is responsible for supervision of the markets and ensuring the safety and soundness of the financial sector in Luxembourg. 

The CCSF published Circular 17/654 to provide a regulatory framework for financial institutions on IT outsourcing to public cloud service providers. Circular 17/654 provides specific guidance on: management of outsourcing risks, business continuity, systems security, monitoring of activities, contractual clauses and the right to audit.

Google Cloud’s contracts for financial institutions in Luxembourg address the requirements in Circular 17/654. We have also created mappings to the guidelines for both GCP and Google Workspace to assist you with understanding how we can support you with meeting the requirements and assess us as an outsourced service provider. Google Cloud is committed to addressing these requirements regardless of how financial institutions choose to use our services.


  ISO/IEC 27001

Learn more

ISO/IEC 27017

Learn more

ISO/IEC 27018

Learn more