Anti-Money-Laundering Duties for Real Estate Agencies: What SEPBLAC Requires
Anti-Money-Laundering Duties for Real Estate Agencies: What SEPBLAC Requires
Property is where dirty money likes to hide. A single transaction moves hundreds of thousands of euros, a deed makes the funds look clean, and a quick resale adds a legitimate capital gain on top. That is exactly why Spanish and EU law treat real estate as a high-risk sector โ and why your agency is legally on the hook, whether or not anyone ever handed you a manual.
If you intermediate the sale or purchase of property in Spain, you are a *sujeto obligado* ("obliged subject") under Law 10/2010 on the prevention of money laundering and terrorist financing. That is not optional, and "I'm just the intermediary" is not a defense. This article lays out what the law and SEPBLAC โ Spain's Financial Intelligence Unit and supervisor โ actually require, in plain terms.
Are you an obliged subject? (Probably yes)
Law 10/2010 lists real estate agents and developers among its obliged subjects. In practice:
- Sale intermediation: if you broker the buying or selling of property, you are obliged, full stop โ regardless of the price.
- Letting intermediation: rental brokerage falls in only when the monthly rent reaches or exceeds โฌ10,000 per month, the threshold introduced across the EU by the 5th AML Directive.
So a boutique agency closing a โฌ180,000 flat sale has the same core duties as a large firm โ even if the deal feels small and the buyer is a lifelong neighbour.
What SEPBLAC actually requires
The obligations break down into a handful of pillars. None of them is exotic; the failures are almost always about *not doing them consistently* and *not being able to prove you did*.
1. Customer due diligence (KYC)
You must formally identify every client before the business relationship, with a valid document, and keep a copy. When a company is involved, you also have to identify the beneficial owner (*titular real*) โ the actual human behind the corporate structure, typically anyone owning or controlling more than 25%.
This is the step most agencies do informally ("I photographed his DNI") and then can't reconstruct in a file 18 months later. If you want the mechanics of doing this cleanly over WhatsApp, we cover it in this guide to automating KYC and DNI checks.
2. Source of funds
SEPBLAC has repeatedly flagged weak verification of the origin of funds as the sector's soft spot. For higher-risk operations you need to understand โ and document โ where the money is coming from: a mortgage, a property sale, savings, an inheritance. A buyer paying a large sum with no plausible economic story is a classic red flag.
3. Risk assessment and special examination
You have to assess the risk of each client and operation and apply a *special examination* to anything unusual: transactions with no apparent economic purpose, disproportionate to the client's profile, involving high-risk jurisdictions, or structured to fall just under thresholds.
4. Internal organisation
Every obliged subject needs:
- A written AML manual with your policies and procedures.
- A designated representative before SEPBLAC (*representante ante el SEPBLAC*) โ the internal person responsible for compliance and communication with the authority.
- Ongoing training for staff so they can spot indicators.
Small agencies can scale this proportionately, but "proportionate" is not "nonexistent."
5. Record retention: 10 years
You must keep the due-diligence documentation for a minimum of ten years. That includes ID copies, beneficial-ownership records, the source-of-funds evidence and your risk analysis. In an inspection, if it isn't in the file, it didn't happen.
Ten years of client IDs also means a data-protection obligation running in parallel โ keeping the copies you're legally required to hold without breaching GDPR. We wrote a separate piece on how to store client ID copies without breaking GDPR.
6. Reporting to SEPBLAC
Two distinct duties people confuse:
- Suspicious transaction reports (*comunicaciรณn por indicios*): when you detect facts that may indicate money laundering, you must report to SEPBLAC โ and you must not tip off the client. This can happen before, during or even after a transaction, and abstaining from a suspicious deal does not remove the duty to report it.
- Systematic/negative reporting: obliged subjects also file periodic reports to SEPBLAC, including a "nil" declaration when there is nothing to report in the period.
The cash rule you can't ignore
Separate from Law 10/2010 but firmly in the same territory: since Law 11/2021, any transaction of โฌ1,000 or more cannot be paid in cash when one of the parties acts as a business or professional. Because an agency is always a professional, that limit bites on your deals. (The limit rises to โฌ10,000 only when the payer is a non-resident individual not acting as a business.) Crucially, it applies to the *whole operation* โ you cannot split a โฌ30,000 payment and settle "just a small part" in cash.
What happens if you don't comply
Law 10/2010 has one of the harshest sanction regimes in Spanish administrative law. Failing to keep records, for example, is a serious infraction with fines starting at โฌ60,001. For very serious infractions the penalty can reach up to โฌ10 million โ or up to five times the amount involved in the transaction in the worst cases. Add reputational damage and possible suspension of activity, and "we'll deal with it if we're inspected" becomes an expensive bet.
What's changing: the EU AML package (2027)
The rules are about to become more uniform across Europe. The EU's new Anti-Money-Laundering Regulation (AMLR, EU 2024/1624) becomes directly applicable on 10 July 2027, without needing national transposition. Two headline changes for agencies:
- An EU-wide โฌ10,000 cap on cash payments in a business context.
- Mandatory customer identification for cash payments of โฌ3,000 or more.
A new EU authority, AMLA, will supervise the highest-risk cross-border financial institutions, while real estate agents continue to be inspected by national supervisors โ now under harmonised rules. The direction of travel is clear: less discretion, more documented process.
How to comply without drowning in paperwork
The common thread across every pillar above is documentation you can retrieve on demand. Most agencies fail inspections not because they had bad intentions, but because the ID copy, the beneficial-owner note and the source-of-funds evidence live in three different WhatsApp chats and an email nobody can find.
The practical fix is to capture the identity data structurally at the moment the client sends it, instead of screenshotting documents into a phone gallery. Turning a photographed DNI or company deed into structured, searchable, retainable data is exactly the kind of manual step that AI document extraction removes โ so the compliance file builds itself as you work.
If your KYC and document intake still run on manual retyping, WhappScan turns documents sent over WhatsApp into structured data in seconds โ see how at whappscan.com.