The ethics & compliance function is being redesigned by Brussels regulation. AMLR splits the compliance role, DORA rewrites operational resilience, MiCA opens a new perimeter. Here is the 2026 map - and what to do before the deadlines.
1. 2026 is a preparation year
For Belgian compliance functions, 2026 is the last full year before the biggest regulatory reset in a generation. The EU AML package - Regulation (EU) 2024/1624 (AMLR) and Directive (EU) 2024/1640 (AMLD6) - becomes applicable on 10 July 2027. DORA has been applicable since 17 January 2025 and MiCA since December 2024. Whistleblowing obligations are fully in force. And Belgium is under enhanced follow-up at the FATF, which means intensified inspections of accountants, auditors and other non-financial obliged entities.
This article maps what actually changes for ethics & compliance in Belgium, and what a compliance function should do between now and July 2027.
2. AMLR and AMLD6: the compliance function is split in two
The AMLR applies directly (no national transposition needed) from 10 July 2027; AMLD6 must be transposed by the same date. The new regime is supervised at EU level by AMLA, operational since mid-2025.
The dual function. The package introduces two distinct roles: the compliance manager for financial institutions, and the compliance officer for other obliged entities. This is not a cosmetic change: responsibilities, qualifications and accountability differ. Belgian entities need to map which function applies to them - and who carries it - before the deadline.
A wider perimeter. New obliged entities join the regime: crowdfunding platforms, dealers in luxury goods, and - from 10 July 2029 - professional football clubs, their holding companies and player agents. Crypto-asset service providers are already in scope as obliged entities under the extended regime.
Harmonised tools. The AMLR sets common customer due diligence requirements, a harmonised risk assessment methodology, and a future central EU register of beneficial ownership (BORIS), which will progressively interconnect national registers - including the Belgian UBO register. Screening and UBO verification will become more automated and more auditable.
3. DORA: operational resilience around the compliance function
DORA (Regulation (EU) 2022/2554), applicable since 17 January 2025, is not an AML text, but it changes the compliance environment for financial entities: ICT risk management, incident reporting, digital operational resilience testing and third-party risk management (including cloud and outsourced services). For compliance functions, the practical consequence is twofold:
Outsourcing of compliance tasks (including AML screening or monitoring) must be governed with the same rigour as any critical ICT service.
The register of information and the risk register must now cover ICT and third-party risks alongside AML risks - which is exactly what a GRC platform like Reesk.io structures.
4. MiCA: crypto-assets inside the regulated perimeter
MiCA (Regulation (EU) 2023/1114), applicable progressively since December 2024, brings crypto-asset service providers (CASPs) into a full authorisation regime. CASPs are obliged entities under the AML framework, subject to customer due diligence, sanctions screening and the travel rule. For Belgian institutions interacting with crypto-asset businesses, this means: verify the CASP's authorisation status, apply enhanced due diligence where relevant, and screen the counterparty against sanctions and PEP lists just as you would any financial institution.
5. Whistleblowing: fully in force, inspections arriving
The Act of 28 November 2022, transposing the EU Whistleblower Protection Directive (2019/1937), requires private legal entities with 50 or more workers to operate internal reporting channels and protect whistleblowers (obligations entered into force on 15 February 2023, extended to 50+ entities on 17 December 2023). Many entities set up a channel in a hurry. The next phase is enforcement: documented procedures, case management, protection against retaliation. A whistleblowing policy that exists only on paper is now a liability.
6. FATF: why Belgian professions are in the spotlight
Belgium is under enhanced follow-up at the FATF. The consequence is practical: increased controls of non-financial obliged entities - accountants, tax advisers, notaries, real estate agents, auditors. For these professions, reporting to the CTIF-CFI and oversight by the ITAA and the IRE are under closer scrutiny. Inspectors focus on documentation: risk assessment, client files, screening evidence, training records. The entities most exposed are those where the compliance officer role is a title rather than a function.
7. What to do between now and 10 July 2027
A pragmatic checklist:
Map the future function. Determine whether your entity will fall under the compliance manager or compliance officer regime, and who will carry it. Plan the governance around it - the single-person AMLCO model is at risk.
Update the risk assessment. Product, channel, customer and geography granularity. This is the document inspectors read first.
Expand the screening scope. Sanctions, PEP and adverse media coverage must extend to the new perimeters (crypto, crowdfunding, and later football). Keep an audit trail of every screening and every hit cleared.
Reinforce training. Individual assessment, documented completion, and a refresh cycle. Attendance is no longer enough.
Audit the whistleblowing setup. Channel, procedure, case management, protection - and evidence of each.
Connect the risk map. AML risks, operational resilience (DORA) and third-party risks belong in one register, with one owner and one reporting line to the board.
Subscribe to a regulatory watch. The AMLR application is two years of secondary measures, guidelines and national choices away. Entities that monitor developments monthly - not when the inspection letter arrives - will be ready.
8. How Pideeco can help
Pideeco is a Brussels-based compliance and risk consulting firm (activity under NBB, CSSF and AMF oversight) serving more than 200 clients across Belgium and Luxembourg. We combine senior advisory, certified training and proprietary tools:
Ethics & compliance: definition, framework and best practices in Belgium - the pillar page with the full framework.
Compliance consultancy services - gap analysis and AMLR readiness, starting with a one-day assessment.
Reesk.io - risk register and GRC platform to structure the risk map.
Pideeco Learning - certified e-learning with individual certificates, including sanctions and MiCA courses.
RegWatch - regulatory watch across Belgium, Luxembourg, France and the EU.
Contact Pideeco - Avenue Louise 137, 1050 Brussels - to schedule your AMLR readiness assessment.






