← All articlesEstate & letting agents15 June 2026 · 6 min read

PSRA licence renewals and AML: keeping your file inspection-ready

How PSRA-licensed estate and letting agents keep an inspection-ready AML file — risk assessment, CDD records, training logs and STR evidence in one place.

Your PSRA licence comes up for renewal every year, and every year the same uncomfortable question surfaces: if the Property Services Regulatory Authority asked to see your AML file tomorrow, would it stand up? For many small estate and letting agencies, the honest answer is "mostly" — a policy document written years ago, CDD records scattered across email threads, and a training log that stops in the year the template was downloaded. With the EU's new AML Regulation (the AMLR, Regulation (EU) 2024/1624) applying from 10 July 2027, that file needs to be in order now, because the rulebook it is measured against is about to change.

This post sets out what an inspection-ready AML file looks like for a PSRA-licensed firm, and how the AMLR changes it.

Why does the PSRA care about your AML file?

The PSRA wears two hats. It is your licensing body under the Property Services (Regulation) Act 2011, and it is also the AML competent authority for estate agents, letting agents, auctioneers and property management firms under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. That means the body that grants and renews your licence is the same body that supervises your AML compliance. A firm that treats AML as an afterthought is exposing the licence it trades on.

From 10 July 2027, the substantive AML rules move from the CJA 2010 to the AMLR, a directly applicable EU regulation. Your supervisor stays the same. The rulebook it applies does not.

What belongs in an inspection-ready file?

Think of your AML file as the evidence that your programme exists in practice, not just on paper. At a minimum it should contain:

  • A current business-wide risk assessment. Your written assessment of the money-laundering and terrorist-financing risks your agency actually faces — your client types, your locations, the mix of sales and lettings, how you take on clients. It should be dated, reviewed periodically, and reflect your business as it is today.
  • AML policies, controls and procedures. Written procedures your staff can actually follow: when CDD is triggered, what documents are collected, when enhanced due diligence applies, how suspicions are escalated.
  • CDD records for vendors and purchasers. Identity documents, verification evidence, beneficial-ownership information for corporate clients, and a record of the risk rating applied to each client.
  • RBO extracts and discrepancy records. Since April 2021, designated persons must obtain an extract from the Register of Beneficial Ownership before entering a new business relationship with a company, and must report discrepancies between the register and what CDD reveals. Keep the extract and your comparison note on file.
  • A training log. Who was trained, on what, and when — including new joiners.
  • STR records. If you have filed Suspicious Transaction Reports, evidence of dual submission: to FIU Ireland via the goAML portal and to the Revenue Commissioners via ROS.
  • Role designations. A record of who your MLRO or compliance officer is, and how reports reach them.

What will an inspector-ready file look like under the AMLR?

The AMLR keeps the same architecture — risk assessment, CDD, monitoring, reporting, records — but changes important details. For a property firm, the ones to build into your file now are:

  • The CDD threshold for occasional transactions drops from €15,000 to €10,000, and occasional cash transactions of €3,000 or more trigger limited CDD.
  • An EU-wide €10,000 cap on cash for commercial transactions applies, covering single or linked payments — relevant to deposits and booking payments.
  • Two prescribed compliance roles arrive: a board-level compliance manager and a compliance officer of sufficiently high standing, with the compliance officer also responsible for targeted financial sanctions from 10 July 2027.
  • Records must be retained for 5 years and then deleted — so your file needs a deletion routine, not just a retention one.
  • Letting activity for tenancies with monthly rent of €10,000 or more is expressly in AMLR scope, which matters if you handle high-value lettings.

A hypothetical inspection, walked through

Imagine — purely as a hypothetical — a three-person agency in a county town. The PSRA asks for its AML documentation. The firm produces a policy dated four years ago, CDD files for most but not all recent sales, and no record of RBO extracts for its two corporate vendor clients. Nothing sinister has happened, but the file cannot demonstrate that the firm's controls operate consistently. That gap — between having controls and being able to evidence them — is what an inspection exposes. The fix is not more paperwork; it is keeping the paperwork you already generate in one organised, dated place.

What to do now

  1. Pull your AML file together in one location — physical or digital — and date-stamp what you find.
  2. Refresh your business-wide risk assessment if it no longer describes your current business.
  3. Check every active client file for CDD evidence, and every corporate client for an RBO extract and discrepancy note.
  4. Bring your training log up to date and diarise the next session.
  5. Update your procedures for the AMLR thresholds — €10,000 occasional transactions, €3,000 occasional cash, the €10,000 cash cap.
  6. Decide who will hold the compliance manager and compliance officer roles from 10 July 2027, and record it.
  7. Diarise a full AMLR review well before the application date.

Where CompliDesk fits

CompliDesk Ireland keeps all of this — risk assessment, CDD records, RBO evidence, training log, STR tracker — in one inspection-ready workspace built for the AMLR from day one. If you would like to see how it works for a PSRA-licensed firm, book a demo.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist