Pideeco
}

Ethics & Compliance

Ethics & Compliance:
what a defensible framework really requires

"Ethics" and "compliance" are two disciplines and one objective: protecting your institution. Here is what a framework that withstands NBB, CSSF and FSMA scrutiny looks like - and how senior practitioners actually build it.

Definition

Ethics and compliance: two disciplines, one objective

Ethics is the set of moral principles and standards of conduct that guide decisions, choices and actions. Compliance is the adherence to laws, regulations, rules and policies. The two disciplines are complementary: compliance defines what the law requires, ethics defines what the company stands for. One without the other leaves a framework either toothless or blind.

Ethical foundations

Code of conduct, conflicts of interest management, ESG commitments, whistleblowing culture.

Legal and regulatory compliance

Risk assessment, policies and procedures, controls, training, monitoring and reporting.

For Belgian obliged entities, this distinction matters in practice. Supervisors do not audit ethics as such - they audit whether the framework, controls and documentation demonstrate that risks are identified, mitigated and monitored. A code of conduct that nobody enforces, or a training programme without assessment, is a compliance gap, not an ethics programme.

Framework

The building blocks of an ethics & compliance framework

01

Tone at the top

The board and senior management set the standards. In practice: an ethics & compliance charter approved at the highest level, and a clear allocation of responsibilities.

02

Code of conduct

A document reflecting the company's DNA, its values and its commitments: integrity, protection of people and assets, transparency, prevention of fraud and conflicts of interest.

03

Conflicts of interest management

Policies, procedures and controls to identify, report, manage and resolve conflicts - including a conflicts register.

04

Risk-based policies and procedures

Customer acceptance, KYC/KYB and enhanced due diligence, screening of business partners, record keeping, reporting to the FIU (CTIF-CFI in Belgium).

05

Three lines of defence

Business functions own the risks, the compliance function (AMLCO, compliance officer) oversees, internal audit provides independent assurance.

06

Training and awareness

Obligatory for all relevant staff, with individual assessment - not mere attendance.

07

Monitoring, reporting and continuous improvement

Activity reports, gap analysis, remediation plans, and a regulatory watch to anticipate change (see AMLR 2027).

Belgium & EU

What Belgian regulators expect

Institutions supervised by the NBB (banks, payment and e-money institutions, insurers, asset managers) and the FSMA (markets, distribution) must meet prudential expectations on governance, AML/CFT and operational resilience. Luxembourg-based entities fall under CSSF supervision with the same substance.

Since the Law of 18 September 2017, Belgian accountants, tax advisers, notaries, bailiffs, real estate agents, auditors and other designated professions are obliged entities under the AML/CFT regime, with direct obligations: customer due diligence, beneficial owner identification, reporting to CTIF-CFI, and designation of a compliance officer.

Regulation (EU) 2024/1624 (AMLR) becomes directly applicable on 10 July 2027, and Directive (EU) 2024/1640 (AMLD6) must be transposed by the same date, under the supervision of the new EU authority AMLA. The package extends the scope to new obliged entities - crowdfunding platforms, dealers in luxury goods, and from 10 July 2029 professional football clubs, their holding companies and player agents - and introduces a dual function: compliance manager for financial institutions, compliance officer for other obliged entities.

Belgium is under enhanced follow-up at the FATF. In practice, this means intensified inspections of accountants, auditors and other non-financial obliged entities. The gap between what the law requires and what many firms actually document is becoming the main inspection trigger.

Whistleblowing (Act of 28 November 2022, channels mandatory for private entities with 50+ workers), sanctions and asset freezing (EU and UN regimes), and - for the financial sector - DORA (applicable since 17 January 2025) and MiCA (progressive application since December 2024) reshape the risk map around the compliance function.

Gap analysis

Common gaps found in gap analyses

Based on our gap analyses across Belgian and Luxembourgish entities, the recurring weaknesses are:

Risk assessment not granular enough (by product, channel, customer type, geography) or not updated.

Code of conduct generic, not adapted to the company's activities.

No conflicts-of-interest register, or an empty one.

Training delivered without individual assessment or documentation.

Screening performed without an audit trail (no evidence of what was checked, when, and why a hit was cleared).

The AMLCO or compliance officer carrying the whole load with no governance around the function.

No regulatory watch: the entity discovers new obligations after the deadline.

Pideeco difference

Tools and expertise: the Pideeco difference

A framework is only as good as the people who own it and the systems that document it. Pideeco combines a senior consulting team with proprietary tools:

Pideeco difference

Senior practitioners, not a delivery factory

Engagements are led by consultants with hands-on experience inside European financial institutions - the same people who design the framework stay accountable through implementation.

Expert design, accountable practitioners, documented execution, continuous updating - that is what makes an ethics & compliance framework defensible in practice.

FAQ

Frequently asked questions

What is the difference between ethics and compliance?+
Ethics is the set of moral principles and standards of conduct that guide decisions and actions. Compliance is the adherence to laws, regulations, rules and policies. Ethics defines what the company stands for; compliance defines what the law requires.
What does an ethics & compliance framework include?+
A code of conduct, conflicts-of-interest management, risk-based policies and procedures (KYC/KYB, screening, reporting), a three-lines-of-defence organisation, training with assessment, and monitoring with documented reporting.
Who needs an ethics & compliance programme in Belgium?+
Financial institutions supervised by the NBB, the FSMA or the CSSF, and non-financial obliged entities under the Law of 18 September 2017 (accountants, tax advisers, notaries, real estate agents and other designated professions). The EU AML package extends this scope from 10 July 2027, and to professional football from 10 July 2029.
What are the consequences of non-compliance in Belgium?+
Administrative and criminal sanctions, reports to CTIF-CFI, reputational damage, and increased scrutiny under the FATF enhanced follow-up. Structural weaknesses in the internal framework can even be used to demonstrate criminal intent in enforcement cases.
How can Pideeco help?+
Pideeco is a Brussels-based consulting firm whose activity is supervised under NBB, CSSF and AMF oversight. Senior practitioners design and implement ethics & compliance frameworks, deliver certified training and proprietary tools, and keep institutions current through RegWatch.

Next step

Ready to test your framework
against supervisor expectations?

Start with a gap analysis: one day, a documented report, a remediation roadmap.