AML & KYC in Belgium is governed by a layered framework that combines EU directives, national legislation, and sector-specific guidance from multiple supervisory authorities. Belgium has implemented successive EU Anti-Money Laundering Directives into domestic law, most recently through the Act of 18 September 2017 on the prevention of money laundering and terrorist financing, as amended. Businesses operating in Belgium - whether in finance, real estate, legal services or accounting - face concrete, enforceable obligations that carry significant penalties for non-compliance. This guide covers the legal framework, who is subject to it, what customer due diligence requires, how supervisors enforce the rules, and what recent changes mean for your organisation.
The Belgian AML legal framework and its supervisory architecture
The cornerstone of Belgian AML law is the Act of 18 September 2017, commonly referred to as the AML Act. This statute transposed the Fourth EU Anti-Money Laundering Directive into Belgian law and has since been amended to incorporate elements of the Fifth and Sixth Directives. The Act defines obliged entities, sets out customer due diligence requirements, establishes internal control obligations, and mandates reporting of suspicious transactions to the Financial Intelligence Processing Unit - known by its French acronym CTIF-CFI.
Belgium operates a multi-supervisor model. The National Bank of Belgium (NBB) supervises credit institutions, payment institutions, and certain insurance undertakings. The Financial Services and Markets Authority (FSMA) oversees investment firms, insurance intermediaries, and certain other financial sector participants. The Institute for Tax Advisors and Accountants (ITAA), the Belgian Institute of Registered Auditors (IBR-IRE), and the bar associations supervise their respective professional categories. The Federal Public Service Economy handles certain non-financial sectors, including real estate agents and diamond traders.
Each supervisor publishes its own circulars and guidance notes, which means that the practical interpretation of the AML Act can differ meaningfully across sectors. A common mistake made by foreign groups entering Belgium is to assume that group-level AML policies automatically satisfy Belgian supervisory expectations. In practice, local adaptation is required, and supervisors will assess whether the Belgian entity has genuinely internalised the framework rather than simply appended a Belgian annex to a global document.
Who qualifies as an obliged entity under Belgian AML rules
The AML Act defines obliged entities broadly. The category covers credit institutions, financial institutions, auditors, external accountants, tax advisors, notaries, lawyers (in specific circumstances), real estate agents, trust and company service providers, and dealers in high-value goods. Diamond traders operating in Antwerp fall under a dedicated supervisory regime given Belgium';s historic role in the global diamond trade.
For lawyers and notaries, the obligation to apply customer due diligence and report suspicious transactions is limited to situations involving financial or real estate transactions, the creation or management of companies, and similar activities. Legal professional privilege is preserved for core advisory and litigation work, but the boundary between privileged and non-privileged activities requires careful assessment.
Crypto-asset service providers are now firmly within scope. Following the transposition of relevant EU requirements, virtual asset service providers operating in Belgium must register with the FSMA and comply with the full suite of AML obligations, including KYC, transaction monitoring, and suspicious transaction reporting. This is a significant development for fintech businesses and digital asset platforms considering Belgium as a base.
Two practical scenarios illustrate the scope. First, a UK-based accounting firm opening a Belgian branch to serve local clients must register with ITAA and implement a Belgian-compliant AML programme before onboarding any client. Second, a real estate developer selling residential units in Brussels must apply customer due diligence to buyers, verify the source of funds, and report any transaction that raises suspicion, regardless of whether the buyer is Belgian or foreign.
KYC and customer due diligence requirements in Belgium
Customer due diligence (CDD) is the operational core of KYC in Belgium. The AML Act requires obliged entities to identify and verify the identity of their customers, identify beneficial owners, understand the nature and purpose of the business relationship, and conduct ongoing monitoring. The standard CDD process must be completed before establishing a business relationship or executing a transaction above applicable thresholds.
Beneficial ownership identification is a central requirement. Belgium maintains a UBO Register - the Ultimate Beneficial Owner Register - administered by the Federal Public Service Finance. Obliged entities must consult the UBO Register as part of their CDD process and must not rely on it exclusively; they are required to verify that register information is consistent with information obtained directly from the customer. Companies registered in Belgium are themselves obliged to file accurate UBO information and to update it within one month of any change.
Enhanced due diligence (EDD) applies in higher-risk situations. These include relationships with politically exposed persons (PEPs), transactions involving high-risk third countries as designated by the European Commission, complex or unusually large transactions, and any situation where the risk assessment indicates elevated exposure. EDD requires obtaining additional information on the customer and the source of funds, applying enhanced ongoing monitoring, and in some cases obtaining senior management approval before proceeding.
Simplified due diligence (SDD) is available in limited circumstances where the customer, product, or transaction presents a demonstrably low risk. Belgian supervisors have signalled a cautious approach to SDD: the burden of demonstrating that simplified measures are appropriate rests entirely with the obliged entity. A common mistake is to apply SDD to listed companies or public authorities without documenting the risk rationale.
The risk-based approach is mandatory. Every obliged entity must maintain a written risk assessment covering its customer base, products, delivery channels, and geographic exposure. This assessment must be reviewed regularly and updated when material changes occur. Supervisors will request this document during inspections, and its absence or superficiality is treated as a serious deficiency.
Suspicious transaction reporting and the role of CTIF-CFI
The CTIF-CFI is Belgium';s Financial Intelligence Unit. It receives, analyses, and disseminates financial intelligence to law enforcement and judicial authorities. Obliged entities are required to report to CTIF-CFI whenever they know, suspect, or have reasonable grounds to suspect that funds are the proceeds of criminal activity or are connected to terrorist financing. The reporting obligation is triggered by suspicion, not by certainty.
The tipping-off prohibition is a critical compliance point. Once a suspicious transaction report (STR) has been filed or is being considered, the obliged entity is prohibited from informing the customer or any third party that a report has been made or is under consideration. Breach of this prohibition is a criminal offence. In practice, this creates operational challenges when a client relationship must be managed carefully while an STR is pending.
CTIF-CFI publishes annual reports and typology guidance that are valuable for compliance teams. The unit has highlighted recurring patterns in Belgian financial crime, including the use of complex corporate structures to obscure beneficial ownership, cash-intensive businesses used as laundering vehicles, and the exploitation of real estate transactions. Compliance officers should review CTIF-CFI guidance regularly and use it to calibrate their transaction monitoring scenarios.
The obligation to report extends to attempted transactions. If a customer attempts to execute a transaction that raises suspicion and then withdraws the instruction, the obliged entity must still consider whether an STR is required. Many compliance teams overlook this point, treating the withdrawal of an instruction as the end of the matter.
If your organisation is navigating STR obligations or building a transaction monitoring framework for the Belgian market, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Internal controls, training, and governance obligations
The AML Act imposes detailed internal governance requirements on obliged entities. Every covered entity must designate a responsible person for AML compliance - the AMLCO (Anti-Money Laundering Compliance Officer) - who has sufficient seniority, resources, and access to senior management to discharge the role effectively. In larger organisations, a dedicated compliance function is expected. In smaller firms, the AMLCO role may be combined with other functions, but the individual must still demonstrate genuine competence.
Written policies and procedures are mandatory. These must cover customer acceptance, CDD and EDD procedures, transaction monitoring, STR filing, record-keeping, and staff training. Policies must be approved at board or senior management level and reviewed at least annually. Belgian supervisors pay close attention to whether policies are genuinely implemented or merely exist on paper.
Record-keeping obligations require that CDD documents and transaction records be retained for a minimum of ten years from the end of the business relationship or the date of the transaction. This is a longer retention period than in some other EU jurisdictions and has practical implications for data management and storage.
Staff training is a legal obligation, not an optional best practice. All relevant staff must receive initial training when they join and periodic refresher training thereafter. Training must cover the recognition of suspicious activity, internal reporting procedures, and the legal consequences of non-compliance. Supervisors will assess training records during inspections.
A non-obvious requirement is that obliged entities must have an anonymous internal reporting channel through which staff can report concerns about AML compliance without fear of retaliation. This whistleblower protection mechanism must be documented and communicated to all relevant staff.
Recent regulatory developments and upcoming changes
Belgian AML regulation has been in a period of active development. The transposition of the Sixth EU Anti-Money Laundering Directive introduced new predicate offences for money laundering, extended criminal liability to legal persons, and harmonised minimum penalties across EU member states. Belgian criminal law was amended accordingly, and prosecutors now have broader tools to pursue money laundering cases.
The EU';s AML package - comprising the new AML Regulation, the Transfer of Funds Regulation recast, and the establishment of the EU Anti-Money Laundering Authority (AMLA) - will have direct effect in Belgium without requiring further national transposition for the regulation itself. AMLA, which will be based in Frankfurt, will directly supervise certain high-risk obliged entities across the EU, including some operating in Belgium. Belgian supervisors will continue to supervise the majority of domestic obliged entities but will work within a framework increasingly shaped by AMLA';s binding technical standards and guidelines.
The UBO Register has been subject to litigation following the Court of Justice of the European Union';s ruling on public access. Belgium adjusted its rules to restrict public access while preserving access for obliged entities and competent authorities. Compliance teams should ensure their CDD procedures reflect the current access rules and do not rely on assumptions about public availability of UBO data.
Crypto-asset regulation under MiCA (Markets in Crypto-Assets Regulation) intersects directly with AML obligations for digital asset businesses. Belgian-registered crypto-asset service providers must comply with both MiCA licensing requirements and the AML framework, including the travel rule for crypto transfers. This dual compliance burden is a significant consideration for any business in the digital asset space.
The FSMA and NBB have both signalled increased supervisory intensity, with more frequent thematic inspections and a greater focus on the quality of risk assessments and transaction monitoring. Fines for AML breaches in Belgium can reach several million euros, and supervisors have shown willingness to use their full range of powers, including public censure and licence withdrawal.
FAQ
What are the main penalties for AML non-compliance in Belgium?
Belgian supervisors have a broad range of enforcement tools. Administrative sanctions include warnings, orders to cease non-compliant conduct, fines that can reach several million euros, and - in serious cases - suspension or withdrawal of authorisation to operate. Criminal penalties under the AML Act and the Criminal Code can result in imprisonment and substantial fines for individuals. Supervisors have become more active in recent years, and public enforcement decisions are published, creating reputational as well as financial consequences. Firms that self-identify deficiencies and remediate proactively are generally treated more favourably than those where problems are discovered during inspection.
How long does it typically take to build a compliant AML programme for a new Belgian entity?
The timeline depends heavily on the size and complexity of the business. A straightforward professional services firm with a limited client base might implement a basic compliant programme within two to three months, covering risk assessment, written policies, CDD procedures, and staff training. A financial institution subject to NBB supervision will face a more demanding process, including regulatory pre-approval of its compliance framework, which can extend the timeline to six months or more. The key constraint is usually the quality of the risk assessment: supervisors expect a genuinely tailored document, not a template, and producing one requires a thorough understanding of the business model.
Does Belgium require a local AML compliance officer, or can the function be centralised in another EU country?
Belgian supervisors generally require that the AMLCO function be genuinely accessible and effective at the local level. For entities subject to NBB or FSMA supervision, the expectation is that a senior individual within the Belgian entity holds the AMLCO role and has direct access to management and the board. Centralising the function entirely in another jurisdiction - even within the EU - is unlikely to satisfy Belgian supervisory expectations, particularly for credit institutions and investment firms. Group-level support is acceptable and encouraged, but it must supplement, not replace, a locally accountable compliance function. This is a point that frequently surprises international groups accustomed to more permissive approaches in other jurisdictions.
Conclusion
AML & KYC in Belgium operates within a rigorous and actively enforced framework. Obliged entities face concrete obligations across customer due diligence, beneficial ownership verification, suspicious transaction reporting, internal governance, and staff training. Recent EU-level developments - including AMLA';s establishment and the direct application of the new AML Regulation - will further raise the compliance bar. Businesses entering or operating in Belgium should treat AML compliance as a substantive operational priority, not a box-ticking exercise.
VLO Law Firms advises international clients on AML & KYC matters in Belgium. We can assist with risk assessments, compliance programme design, AMLCO support, regulatory correspondence, and suspicious transaction reporting procedures. To request a consultation, contact: info@vlolawfirm.com