AML Compliance for Real Estate: A 2026 Operator's Guide for Property-Services Shops

A familiar pattern has emerged across the property-services industry over the past 18 months. A property manager asks for proof that the LLC behind a property has verified its beneficial ownership. A title company contacts the owner before closing to confirm whether a cleaning service on file has been screened against OFAC sanctions lists. A buyer's attorney requests documentation related to the source of funds connected to a maintenance invoice issued three months earlier. These requests were once uncommon for contractors, but they are becoming routine.
Property managers, lettings agents, and title firms are increasingly extending AML compliance requirements to the contractors who service their portfolios. If your business cleans, secures, repairs, inspects, or maintains properties owned by trusts, LLCs, or other corporate entities, someone higher up the chain may ask for records your company cannot yet provide in time for an audit.
This guide is intended for owners of small to mid-sized property-services shops who need a practical overview of AML compliance requirements for real estate in 2026. It explains the implications of FinCEN, FATF, and EU regulations, outlines the operational changes these requirements may demand, and highlights how existing safety and JSA documentation practices can provide a compliance advantage.
.webp?updatedAt=1752664594767)
What AML in real estate actually means
According to FATF guidance, real estate professionals - including agents, brokers, property managers, and developers - may be subject to requirements related to customer identification, beneficial ownership verification, transaction monitoring, recordkeeping, and the reporting of suspicious activity, depending on the jurisdiction and regulatory framework.
In many ways, AML compliance is the financial equivalent of OSHA recordkeeping (the safety records regulators can ask to see). Regulators may not review documentation on a daily basis, but when an audit, investigation, or compliance review occurs, the required records must be available and complete.
Why criminals keep choosing property
Property is long-lasting, valuable, and slow-moving. One transaction can transfer millions of dollars in a single step. Ownership may be held through nominee names, shell entities, or layered trusts that require examiners months to unravel. Leases, sales, and resales give launderers the chance to add funds. As the asset gains value, criminal proceeds are cleaned and can even turn a profit. The most frequent complaint from operators is that no one has informed the companies they work with. A standard HVAC service contract for a unit in a residential building could be subject to FinCEN's new rules if ownership is held through an institution.
How money laundering actually moves through property
Most schemes look unremarkable:
- Nominee ownership. Someone else may sign the contract to conceal the actual buyer.
- Layered payments. Funds move through multiple banks, businesses, or jurisdictions before reaching escrow.
- Rapid resale. A property is purchased with minimal improvements and then resold to convert dirty money into clean capital.
- Structured cash. Large purchases are split into smaller amounts to stay below reporting thresholds.
None of these trigger alarms if your records are paper-based and your team does not have a documented process for flagging them.
The 2025-2026 regulatory shift property services cannot ignore
Four developments have changed the way small property-services providers need to operate, and most of these changes have occurred within the past 18 months.
FATF is pushing obligations down the property chain
FATF's 2022 State of Effectiveness review summarized in the RUSI policy brief found only 19% of 120 countries had high or substantial effectiveness at confiscating proceeds of crime, which is why FATF has pressed supervisors to push obligations further down the chain. That pressure shows up as title companies, managing agents, and lettings firms adding AML clauses to vendor contracts that didn't have them two years ago.
What the new US, UK, and EU rules require
FinCEN's Residential Real Estate Rule, codified at 31 CFR § 1031.320, is effective December 1, 2025, with reporting required for closings on or after March 1, 2026. It covers non-financed transfers of 1-4 unit residential property to legal entities or trusts. There is no dollar floor: seller financing, hard-money lenders, and all-cash LLC purchases all trigger it.
The Corporate Transparency Act began its BOI regime January 1, 2024, but after early-2025 litigation, FinCEN announced it will not issue fines or penalties for BOI reporting against US persons or domestic reporting companies. Obligations now apply only to certain foreign entities registered to do business in the US.
The UK's Money Laundering Regulations 2017 put estate and lettings agents under HMRC supervision with CDD, beneficial ownership, recordkeeping, and SAR obligations. The EU's 2024 AML package broadens obliged-entity scope and adds retroactive beneficial-ownership rules up to 10 years for foreign entities owning EU real estate.
What this means for a property-services operator
If you manage real estate owned by trusts, business entities, or foreign owners, you will need to:
- Identify the owner, including the beneficial owner of any trust or LLC.
- Maintain records of contracts, customer payments, and service-visit documentation for five to seven years.
- Monitor for and report suspicious activity connected to the properties you manage.
- Provide documented training on these requirements for every technician.
The most commonly cited AML issue is the lack of clarity around who is responsible for compliance. Is it the compliance officer, the operations lead, or every employee? In small businesses, responsibilities are often left undefined until an audit raises the question.
A pattern across multi-trade contractors moving from paper to digital compliance
Across the property-services and multi-trade companies that have shifted from paper-based compliance to digital systems over the past two years, the same scenario often occurs. One example is a mid-sized multi-trade contractor operating across Texas with field workers who are subject to OSHA safety requirements. The documentation gap revealed during safety audits is often the same gap that appears in AML records when a property owner requests documentation.
During an OSHA review, the contractor was required to provide safety-training records for crews working on a recurring commercial real estate contract. The records existed in a sense - in paper binders, in three supervisors' trucks, on a shared drive, and occasionally in the trainer's memory. However, the contractor was unable to produce clear, signed, and dated records within the auditor's review window. The gap resulted in a penalty of thousands of dollars. The training had taken place. The problem was record retrieval, not the underlying activity.
Leadership gathered employee training records into a central digital system. Every completion date, signature, and certification was recorded for each technician and made accessible on demand. The same process was extended to the capture of customer IDs, beneficial ownership documents, timestamped service-visit logs, and payment-method notes recorded at the end of each job.
Two years later, audits were completed with data gathered in minutes rather than days. Staff initially resisted the additional sign-off procedures. Office staff had to enter six weeks of training-history data, and one supervisor resigned when the system was launched. In retrospect, the resistance was due to how the digital workflow was implemented rather than what it required.
It is a combination drawn from patterns observed across several operators, with specifics tied to the version of the standard being followed.
The compliance process runs in three operational stages
AML compliance is not just a step at closing. It begins at onboarding and continues through closeout, followed by the required records-retention period.
Step 1: Customer due diligence done at the doorstep
Before signing a service contract for a property owned by a company, confirm the following:
- Complete legal name, registered address, and identification number of the primary owner.
- Documentation proving the ownership of the property being serviced.
- Identification of the ultimate beneficial owner of any LLC, trust, or holding company.
- Screening against OFAC, PEP, and sanctions watchlists.
- A clear explanation of who is making the payment and the source of the funds.
If the principal refuses to identify the beneficial owner or insists a third party will handle payment without explanation, that is the moment to escalate, not to sign. Your centralized customer records need all five fields, not three of five.
Step 2: The red flags your field team should catch
A working list tuned for property-services operators:
- Cash payments exceeding $10,000 or structured payments designed to remain below the reporting threshold.
- A third-party payer with no documented relationship to the principal.
- Incomplete or unclear source-of-funds documentation.
- A property being resold within a few months of the work being completed.
- An LLC with no operating history opening a service account.
- Refusal to provide beneficial ownership documentation.
- Service requests related to a "rental" property with no evidence of tenancy.
- An owner refusing technician access to specific floors or rooms.
- Repeated emergency service calls to the same property, with payment always made in cash.
- Incorrect identification or address information on record.
- A sudden increase in service requests immediately before an auction.
- A mid-contract change in the person responsible for payments.
The last six are patterns your field team can identify that no back-office screening tools can detect.
Step 3: Ongoing oversight after the contract goes live
Contractors who handle this correctly track each visit (date, technician, property condition, payment method). They also document any irregularities in writing during the same timeframe, maintain records for the regulator-required period, and provide an internal mechanism for raising issues within 48 hours. UK and EU regulations typically require a minimum of five years of recordkeeping, while US regulations under the Bank Secrecy Act (BSA) require records to be retained for five years from the date the obligation began.
Field teams see what the office never will
Office staff process documents, but field teams visit the properties. Technicians are on-site, speaking with people who claim to live or work there, observing the actual condition of the property, and seeing payment methods change in real time. They can notice the empty rental, the locked room, or the cash envelope. This information only makes its way into company records if there is a workflow that allows technicians to document it without disrupting their work.
The cost of getting it wrong, and the lift of getting it right
Non-compliance can result in significant financial penalties (both US BSA and UK MLR regulations carry six-figure risk exposure), revoked or suspended operating permits, civil liability, criminal responsibility for the owner personally, and reputational damage in the property management sector.
According to the 2024 LexisNexis True Cost of Financial Crime Compliance study, the total annual cost of financial-crime compliance across US and Canadian financial institutions reached $61 billion, with 99% of institutions reporting year-over-year cost increases. The property-services operators who absorb those costs cleanly are the ones whose field workflow already captures this data.
The role of AML audits in a property-services shop
AML audits are an independent evaluation of your compliance program to determine whether it is functioning effectively. In most cases, they are required under major regulatory frameworks (such as the US BSA, UK MLR 2017, and the EU 2024 AML package). AML audits are typically conducted at least once a year as a third layer of defense. For property-services shops, an audit usually reviews:
- CDD records for every entity client onboarded during the review period
- Completeness of beneficial ownership documentation
- Transaction monitoring logs and alert disposition
- PEP and sanctions screening checks
- SAR submissions and underlying triggers
- Training records for each technician
- Record retention and the ability to retrieve documents within the regulator’s required timeframe
A customer review posted on the QuickBooks App Store described a company that had implemented Field Promax across four of its businesses, highlighting customer support and customization capabilities that other software products could not match. Audit preparation is one benefit of that customization, since every audit tends to involve different compliance inquiries.
Based on 14 years of customer conversations, the most frequently reported AML audit finding among the shops we work with does not involve missing records. More often, the issue is missing dates or incomplete information within records they already have.

Where mobile compliance workflow earns its keep
The majority of Field Promax customers come from spreadsheets, paper-based systems, or QuickBooks-only setups. This is also where AML records are most often non-compliant: the data exists, but it is not organized, updated, or easily accessible.
For a typical shop with 5-20 technicians that uses paper compliance forms, much of the pre-task documentation is incomplete or illegible, or is no longer legible by the end of the week. Shops that adopt a digital workflow with required fields and missed-form alerts can substantially increase completion rates, since the app does not allow the work order to be completed without the required documentation.
In an 8-tech operation, owners report each tech spends about three to four hours a week on compliance paperwork (JSAs, toolbox talks, customer ID capture, certification check-ins). Shops that move those forms into a mobile compliance workflow claw that back to under 1 hour per tech per week, offsetting much of the headcount cost of layering AML on top of safety compliance.
.webp?updatedAt=1747733768864)
I read every support ticket the platform produces, so I see what compliance breaks look like in the field before they show up in a regulator press release. The new FinCEN Residential Real Estate Rule, the UK MLR supervision regime, the EU 2024 AML package: none of them were written with a 12-tech property-maintenance shop in mind, but obligations roll downhill anyway. Conventional wisdom says wait until your largest property-management client requires it in writing. I disagree.
The shops that pass clean audits aren't the ones that scramble in the 30 days before a deadline. They're the ones whose techs were already filing timestamped service records six months earlier because the mobile workflow made it easier to file than to skip.
- Joy Gomez, Founder of Field Promax
.webp?updatedAt=1752664595764)
A compliance checklist for this quarter
You can make these changes this quarter without having to purchase a separate compliance platform.
- Check current contracts involving trusts or property owned by an entity, and mark them for CDD review.
- Establish a single source of truth for customer ID documents, ownership records, and service visit documentation.
- Include a five-minute mobile form requirement at the end of the job payment process, covering any observed irregularities and ID match verification.
- Every technician should be trained on the red-flag field checklist, with refresher training conducted at least every six months.
- Assign one designated owner to oversee AML compliance, even in a 10-person shop. Uncertainty about ownership is often the reason compliance processes fail.
- Perform an annual audit of your internal systems using the audit checklist mentioned above.

Enterprise compliance systems are typically priced for large financial institutions. Regulators are not lowering their expectations, and the cost of making a mistake now includes both financial penalties and the loss of contracts when property management companies apply vendor AML requirements. Companies that successfully manage this challenge typically handle AML as a separate field-captured workflow integrated into their operations.
Field Promax supports that posture with centralized customer records, timestamped service logs, and audit-ready reporting dashboards that hold up when an auditor asks for the date a record was created.
Sources consulted: RUSI policy brief on FATF asset-recovery effectiveness; FinCEN Residential Real Estate Rule (31 CFR § 1031.320); FinCEN guidance on CTA BOI enforcement; UK Money Laundering Regulations 2017; Stripe summary of the EU 2024 AML package; 2024 LexisNexis True Cost of Financial Crime Compliance, US/Canada.
Conclusion
Property-services providers didn’t ask for an AML system, but they ended up needing one. The companies that adapt well are those that treat compliance as a field-captured workflow rather than a back-office add-on.
