If you hold a PSRA licence, you have two regulators' worth of expectations wrapped into one body. The Property Services Regulatory Authority is your licensing authority under the Property Services (Regulation) Act 2011, and it is also your anti-money laundering competent authority under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. When the PSRA looks at your firm's AML compliance, the question is simple: can you show, on paper or on screen, that you are doing what the Act requires?
For many small agencies the honest answer is "mostly, but it's scattered across Word documents, email threads and someone's memory". That gap is about to matter more. From 10 July 2027, Regulation (EU) 2024/1624 (the AMLR) replaces the substantive AML rulebook your firm currently works under. It is a directly applicable EU regulation, so there is no waiting for Irish transposition. The records the PSRA will expect to see are changing, and the runway to get your file in order is now.
This post walks through what a well-organised AML file looks like for an Irish estate or letting agency, and flags where the AMLR moves the goalposts.
Your firm-level documents: the risk assessment and policies
The foundation of the file is your business-wide risk assessment. This is your written analysis of the money laundering and terrorist financing risks your particular agency faces: the types of property you sell or let, the profile of your vendors, purchasers, landlords and tenants, how you take instructions, and how money moves through your transactions. It should be specific to your firm, not a generic template with the agency name swapped in, and it should be reviewed regularly, with each review dated and recorded.
Sitting on top of that are your AML policies, controls and procedures: who does what, when customer due diligence happens, how staff escalate concerns, and who your MLRO is. Under the AMLR, expectations around compliance governance become more prescriptive. Obliged entities must designate a compliance manager at board or senior management level plus a compliance officer of sufficiently high standing, and from 10 July 2027 the compliance officer also becomes responsible for implementing targeted financial sanctions. If your current file does not clearly name who holds these roles, that is a gap to close before the new regime applies.
Client files: customer due diligence records
For each business relationship, your file should show identity verification for the client, evidence of when it was carried out, and the risk rating you assigned with a note of why. For estate agents that means CDD on vendors as well as purchasers; for letting agents it means landlords and, where in scope, tenants.
The AMLR tightens the thresholds you may have built your procedures around:
- The CDD threshold for occasional transactions drops to 10,000 euro, down from 15,000 euro.
- Occasional cash transactions of 3,000 euro or more trigger limited CDD.
- A directly applicable EU-wide cap of 10,000 euro applies to cash payments for commercial transactions, whether as a single operation or as linked operations.
Cash is rare in Irish property sales, but deposits, holding payments and lettings activity can still brush against these limits. Your procedures, and the file evidencing that staff follow them, need to reflect the new figures.
Letting agents should also note a scope change: under the AMLR, letting activity is in scope for tenancies with monthly rent of 10,000 euro or more. Sales-side estate agency work remains squarely in scope as it is today.
Beneficial ownership: the RBO extract and discrepancy log
Where your client is a company, your file needs more than a CRO printout. Since April 2021, designated persons must obtain an extract from the Register of Beneficial Ownership at rbo.gov.ie before entering a new business relationship, and must report any discrepancy between the register and what your own checks reveal (Regulation 20(3)(b) of SI 110/2019). Your firm registers for designated-person access using the BEN3A1 form, and each extract carries a small fee.
A complete file therefore holds: the RBO extract itself, the beneficial ownership information the client gave you, a recorded comparison of the two, and, where they did not match, your discrepancy decision and any notification made to the Registrar. The AMLR harmonises the beneficial owner test EU-wide at 25 per cent or more ownership interest, direct or indirect, so your identification worksheets should be built around that figure.
Suspicious transaction reports: evidence of dual reporting
Ireland's STR regime is dual-track. Reports go to FIU Ireland via the goAML portal at fiu-ireland.ie and to the Revenue Commissioners via ROS (see revenue.ie), which accepts the goAML-generated XML. Your MLRO must be registered on both systems, and your file should show that registration plus, for any report made, both submission dates and acknowledgements.
Equally important is the internal trail: staff reports of suspicion to the MLRO, and the MLRO's reasoned decision to report or not to report. A "no report" decision with no recorded reasoning is a weak point in any file. Note that Ireland has no threshold transaction reporting regime; reporting here is suspicion-based, not amount-based.
One AMLR addition worth planning for: requests from the FIU must generally be answered within 5 working days, with shorter deadlines for some categories. That is only workable if your records are organised enough to retrieve quickly.
Training and record retention
Your file should include a training log: who was trained on AML obligations, when, and on what content, including new joiners. From a supervisory perspective, undocumented training might as well not have happened.
On retention, the AMLR sets a clear rule: keep records for 5 years, then delete them. That second half is easy to miss. Holding client identity documents indefinitely creates data protection exposure of its own, so your procedures should cover deletion as well as retention.
What to do now
- Pull your current AML file together in one place and list what exists: risk assessment, policies, CDD records, RBO extracts, STR trail, training log.
- Check the date on your business-wide risk assessment. If it has not been reviewed recently, schedule a refresh and record it.
- Confirm your firm has designated-person access to the RBO and that company-client files hold extracts and discrepancy comparisons.
- Confirm your MLRO is registered on both goAML and Revenue ROS.
- Map your CDD procedures against the AMLR thresholds: 10,000 euro for occasional transactions, 3,000 euro for occasional cash, the 10,000 euro cash cap, and the lettings rent threshold.
- Name your compliance manager and compliance officer now, so the roles are embedded well before 10 July 2027.
- Review the full text of Regulation (EU) 2024/1624 on EUR-Lex and keep an eye on PSRA guidance at psr.ie.
Getting AMLR-ready with CompliDesk
CompliDesk is building an AMLR-native compliance platform for Irish designated persons, including PSRA-licensed estate and letting agents, ahead of the 10 July 2027 application date. For a structured starting point, download our AMLR readiness checklist.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.