Monsiegesocial Logo

Anti-money-laundering procedure in Belgium: obligations of obliged entities

Anti-money-laundering procedure in Belgium: obliged entities, KYC due diligence, suspicious-transaction report to the CTIF and UBO register, under the 2017 law.

T

The Monsiegesocial team

Published on 3 mars 2023Updated on 29 juin 202610 min read
Verified official sources
Compliance desk with client identification documents and a calculator for the anti-money-laundering check

Key takeaways

  • The fight against money laundering in Belgium rests on the law of 18 September 2017, which transposes the European anti-money-laundering directives.
  • Only the obliged entities listed by the law (banks, notaries, chartered accountants, real estate agents, business-address providers, etc.) must set up the procedure.
  • The heart of the procedure is customer due diligence (KYC): identifying the client and its beneficial owner, understanding the relationship, then monitoring operations.
  • Any suspicious transaction is reported to the CTIF, the Belgian financial intelligence unit, and document retention is mandatory.

The anti-money-laundering procedure in Belgium does not concern all companies in the same way. It weighs on a precise list of professions and sectors, called obliged entities, which are on the front line to detect flows of money of criminal origin. The framework is set by the law of 18 September 2017 on the prevention of money laundering and terrorist financing, which transposes the European directives on the matter into Belgian law. For these entities, compliance is not an option: it is a legal obligation, supervised and penalised. This article explains who is obliged, what the due-diligence obligations consist of, how the procedure unfolds step by step, and where it crosses the UBO register and the registration of company service providers.

The reference text is the law of 18 September 2017 on the prevention of money laundering and terrorist financing and the limitation of the use of cash. It replaced the previous law of 1993 and transposes the package of European anti-money-laundering directives, commonly designated by the English acronym AML for Anti-Money Laundering. The objective is twofold: prevent the injection of criminal money into the legal economy and cut off the financing of terrorism.

The logic of the mechanism is preventive. Rather than relying entirely on the police and justice after the fact, the legislator mobilises the professionals who see the financial flows and risky operations pass. These professionals become sentinels: they know their clients, monitor operations and report what is out of the ordinary.

The obliged entities: who must apply the procedure

The procedure only applies to the obliged entities that the law enumerates. These are essentially professions in the financial, accounting, legal and real estate sectors, as well as certain traders. A company that carries out none of these activities does not need to set up an internal mechanism, but it will itself be subject to the checks of its banker, its notary or its accountant.

The main categories of obliged entities

  • Financial institutions

    Banks, payment and electronic-money institutions, life-insurance companies, stockbroking firms.

  • Accounting professions

    Company auditors, chartered accountants and tax advisers, in the exercise of their assignments.

  • Notaries and, in certain cases, lawyers

    Notaries for the acts they draw up; lawyers for a limited list of operations, notably financial or real estate.

  • Real estate agents

    For sale and rental transactions above certain thresholds, a profession already framed by the IPI.

  • Company service providers

    Including business-address providers, who supply a registered office or services linked to the incorporation and management of companies.

  • Dealers in high-value goods

    Notably dealers when the payment is made in cash above the legal ceiling.

This list is not exhaustive and the detail of the activities covered appears in the law. The point to remember: being obliged depends on the nature of the activity, not the legal form. A tax-consulting SRL is obliged, an e-commerce SRL is in principle not, unless it handles high-value goods paid in cash.

Customer due diligence, the heart of the procedure

The central obligation is customer due diligence, often designated by the English acronym KYC for Know Your Customer. Before entering into a relationship, then throughout it, the obliged entity must know who it deals with and why. This vigilance is modulated according to the risk: standard in most cases, enhanced in a high-risk situation, simplified for low-risk situations.

  1. 1

    Identify the client

    Step 1

    Gather the identity of the client, natural or legal person, and verify this identity on the basis of supporting documents (identity card, articles, CBE extract).

  2. 2

    Identify the beneficial owner

    Step 2

    Determine the natural person(s) who really control the client or on whose behalf the operation is carried out, and verify their identity.

  3. 3

    Understand the purpose and nature of the relationship

    Step 3

    Grasp what the client comes to do, the origin of the funds and the economic coherence of the business relationship.

  4. 4

    Assess the level of risk

    Step 4

    Classify the relationship according to the money-laundering risk and adapt the intensity of the checks, from simplified to enhanced vigilance.

  5. 5

    Exercise ongoing vigilance

    Step 5

    Monitor operations throughout the relationship, update the information and detect atypical operations.

Identifying the beneficial owner is the trickiest step. Behind a company may lie a chain of shareholdings; the obliged entity must go back to the natural persons who own or control the client. It is precisely there that the UBO register comes into play.

The UBO register (Ultimate Beneficial Owner) lists the beneficial owners of Belgian companies, ASBLs and other legal entities. Keeping it is a separate obligation that weighs on the companies themselves, but it directly serves the anti-money-laundering procedure: it allows obliged entities to cross-check the identity of the beneficial owner they have identified.

Consulting the UBO register does not, however, exempt the entity from its own checks. If the register's information seems inconsistent or outdated, the obliged entity must carry out its checks and, where applicable, report the discrepancy. Our dedicated guide to the UBO register in Belgium details who must declare there, within what deadlines and with what data.

The suspicious-transaction report to the CTIF

When vigilance reveals a suspicious transaction, the obliged entity does not stop at a refusal of the transaction: it must report the suspicion to the CTIF. The Financial Information Processing Unit (CFI in Dutch) is the Belgian authority that centralises, analyses and directs these reports. It is the country's financial intelligence unit.

The CTIF then analyses the reports received. If the analysis confirms serious indications of money laundering or terrorist financing, it forwards the file to the King's prosecutor. The obliged entities are therefore the first link in a chain that goes from internal control to criminal prosecution, with the CTIF playing the role of filter and switch.

The suspicious-transaction report is not a denunciation: it is a legal obligation that protects the professional as much as it serves the fight against money laundering. Better a clear mechanism than finding yourself explaining why nothing was reported.

AAn obliged chartered accountantfirm in Brussels

Documenting, training and retaining: the support obligations

Vigilance and reporting only hold if they rely on an internal organisation. The law requires each obliged entity to structure its mechanism, in proportion to its size and its risk. For the simplest structures, these obligations remain light; for a financial institution, they are extensive.

ObligationWhat it implies
Risk assessmentIdentify and document the risks specific to the activity and clients, and keep it updated
Internal policies and proceduresFormalise the prevention, detection and internal-control measures
Compliance officerAppoint, according to the size of the structure, a person in charge of the AML mechanism
Staff trainingRaise awareness and train the staff exposed to the money-laundering risk
Document retentionKeep the identification data and the operation documents for the period set by law
The support obligations framing vigilance, to be sized according to the entity's size and risk. Indicative presentation, the detail appears in the law of 18 September 2017.

Document retention deserves particular attention: the client's and beneficial owner's identification data, as well as the documents relating to the operations, must be kept for the period provided by law, in order to be produced in the event of a check or an investigation. The precise period is set by the text; above all, remember the principle of an organised and traceable retention.

Create your company on compliant foundations

Monsiegesocial sets up your company and provides its business address at a provider registered with the FPS Economy, already versed in the anti-money-laundering vigilance requirements.

Penalties and supervision of the mechanism

Compliance with the procedure is supervised by supervisory authorities that vary by sector: the National Bank of Belgium and the FSMA for the financial sector, the FPS Economy for company service providers and certain traders, the professional institutes for the accounting professions, the chambers for notaries and lawyers. These authorities check that obliged entities really apply vigilance and report what they must report.

Breaches expose you to administrative and criminal penalties provided by the law of 18 September 2017. Beyond fines, whose amounts depend on the nature and gravity of the offence, a breach may target the directors and lastingly damage the entity's reputation. For regulated professions such as real estate agents, a lack of vigilance may also weigh on the accreditation. The best protection remains a proportionate, documented and applied mechanism.

Going further

Frequently asked questions

Who is subject to anti-money-laundering obligations in Belgium?

The obliged entities are listed by the law of 18 September 2017. They include banks and financial institutions, notaries, company auditors, chartered accountants and tax advisers, lawyers in certain operations, real estate agents, company service providers including business-address providers, as well as dealers in high-value goods. A company that carries out none of these obliged activities is not required to set up an internal procedure, but remains exposed to the checks of its own providers.

What is the CTIF?

The CTIF, Financial Information Processing Unit (CFI in Dutch), is the Belgian authority that receives and analyses the suspicious-transaction reports of obliged entities. It is the country's financial intelligence unit. When an analysis confirms serious indications of money laundering or terrorist financing, the CTIF forwards the file to the public prosecutor.

What is customer due diligence (KYC)?

Customer due diligence, often designated by the English acronym KYC for Know Your Customer, groups together the measures for identifying and knowing the client. It requires identifying and verifying the identity of the client and its beneficial owner, understanding the purpose and nature of the business relationship, then exercising ongoing vigilance over operations throughout the relationship.

What is the link between the anti-money-laundering procedure and the UBO register?

The UBO register lists the beneficial owners of Belgian companies and other entities. Identifying the beneficial owner is at the heart of anti-money-laundering vigilance: the obliged entity must know who really controls its client. Consulting the UBO register is one of the means of verifying this information, without exempting the entity from its own checks.

What penalties apply for breach of anti-money-laundering obligations?

The law of 18 September 2017 provides for administrative and criminal penalties in the event of breach, imposed by the competent supervisory authorities depending on the sector. Beyond fines, a breach may entail measures against the directors and damage the entity's reputation. The exact amounts depend on the nature and gravity of the offence.

You might also like