Ethics & Compliance
Ethics & Compliance:
what a defensible framework really requires
Definition
Ethics and compliance: two disciplines, one objective
Ethics is the set of moral principles and standards of conduct that guide decisions, choices and actions. Compliance is the adherence to laws, regulations, rules and policies. The two disciplines are complementary: compliance defines what the law requires, ethics defines what the company stands for. One without the other leaves a framework either toothless or blind.
Ethical foundations
Code of conduct, conflicts of interest management, ESG commitments, whistleblowing culture.
Legal and regulatory compliance
Risk assessment, policies and procedures, controls, training, monitoring and reporting.
For Belgian obliged entities, this distinction matters in practice. Supervisors do not audit ethics as such - they audit whether the framework, controls and documentation demonstrate that risks are identified, mitigated and monitored. A code of conduct that nobody enforces, or a training programme without assessment, is a compliance gap, not an ethics programme.
Framework
The building blocks of an ethics & compliance framework
Tone at the top
The board and senior management set the standards. In practice: an ethics & compliance charter approved at the highest level, and a clear allocation of responsibilities.
Code of conduct
A document reflecting the company's DNA, its values and its commitments: integrity, protection of people and assets, transparency, prevention of fraud and conflicts of interest.
Conflicts of interest management
Policies, procedures and controls to identify, report, manage and resolve conflicts - including a conflicts register.
Risk-based policies and procedures
Customer acceptance, KYC/KYB and enhanced due diligence, screening of business partners, record keeping, reporting to the FIU (CTIF-CFI in Belgium).
Three lines of defence
Business functions own the risks, the compliance function (AMLCO, compliance officer) oversees, internal audit provides independent assurance.
Training and awareness
Obligatory for all relevant staff, with individual assessment - not mere attendance.
Monitoring, reporting and continuous improvement
Activity reports, gap analysis, remediation plans, and a regulatory watch to anticipate change (see AMLR 2027).
Belgium & EU
What Belgian regulators expect
Institutions supervised by the NBB (banks, payment and e-money institutions, insurers, asset managers) and the FSMA (markets, distribution) must meet prudential expectations on governance, AML/CFT and operational resilience. Luxembourg-based entities fall under CSSF supervision with the same substance.
Since the Law of 18 September 2017, Belgian accountants, tax advisers, notaries, bailiffs, real estate agents, auditors and other designated professions are obliged entities under the AML/CFT regime, with direct obligations: customer due diligence, beneficial owner identification, reporting to CTIF-CFI, and designation of a compliance officer.
Regulation (EU) 2024/1624 (AMLR) becomes directly applicable on 10 July 2027, and Directive (EU) 2024/1640 (AMLD6) must be transposed by the same date, under the supervision of the new EU authority AMLA. The package extends the scope to new obliged entities - crowdfunding platforms, dealers in luxury goods, and from 10 July 2029 professional football clubs, their holding companies and player agents - and introduces a dual function: compliance manager for financial institutions, compliance officer for other obliged entities.
Belgium is under enhanced follow-up at the FATF. In practice, this means intensified inspections of accountants, auditors and other non-financial obliged entities. The gap between what the law requires and what many firms actually document is becoming the main inspection trigger.
Whistleblowing (Act of 28 November 2022, channels mandatory for private entities with 50+ workers), sanctions and asset freezing (EU and UN regimes), and - for the financial sector - DORA (applicable since 17 January 2025) and MiCA (progressive application since December 2024) reshape the risk map around the compliance function.
Gap analysis
Common gaps found in gap analyses
Based on our gap analyses across Belgian and Luxembourgish entities, the recurring weaknesses are:
Risk assessment not granular enough (by product, channel, customer type, geography) or not updated.
Code of conduct generic, not adapted to the company's activities.
No conflicts-of-interest register, or an empty one.
Training delivered without individual assessment or documentation.
Screening performed without an audit trail (no evidence of what was checked, when, and why a hit was cleared).
The AMLCO or compliance officer carrying the whole load with no governance around the function.
No regulatory watch: the entity discovers new obligations after the deadline.
Pideeco difference
Tools and expertise: the Pideeco difference
A framework is only as good as the people who own it and the systems that document it. Pideeco combines a senior consulting team with proprietary tools:
Pideeco difference
Senior practitioners, not a delivery factory
Engagements are led by consultants with hands-on experience inside European financial institutions - the same people who design the framework stay accountable through implementation.
Expert design, accountable practitioners, documented execution, continuous updating - that is what makes an ethics & compliance framework defensible in practice.
FAQ
Frequently asked questions
What is the difference between ethics and compliance?+
What does an ethics & compliance framework include?+
Who needs an ethics & compliance programme in Belgium?+
What are the consequences of non-compliance in Belgium?+
How can Pideeco help?+
Next step
Ready to test your framework
against supervisor expectations?
Start with a gap analysis: one day, a documented report, a remediation roadmap.






