A missed certificate is rarely just a missed certificate. It can mean a delayed move-in, an unhappy landlord, a tenant complaint, a failed audit or a fine that wipes out the margin on several management instructions. A working agency compliance checklist gives letting and property management teams control over those risks before they become urgent.
The aim is not to create another spreadsheet that someone updates once a month. It is to build a repeatable operating process: every obligation has an owner, a due date, evidence and an escalation route. That matters most when a team is busy, a colleague is away or a portfolio grows faster than headcount.
What an agency compliance checklist should do
A useful checklist separates legal requirements from internal standards, then turns both into tasks that can be evidenced. For each property, tenancy, client and supplier record, your team should be able to answer four questions quickly: what is due, who owns it, where is the evidence, and what happens if it is late?
This is not the same as expecting a property manager to remember every date. Compliance managed from memory is expensive and inconsistent. A central workflow makes work visible across the team and gives directors a clearer view of exposure across the portfolio.
Your exact requirements depend on whether you manage lettings, block management or both, where the property sits within the UK, and the services in your terms of business. England, Scotland, Wales and Northern Ireland do not operate under one identical letting framework. Use the checklist as an operational baseline and have legal or compliance advice confirm how current rules apply to your business.
Agency compliance checklist: the core controls
Business and client-money controls
Start at agency level. Confirm that required memberships, registrations and insurance are current, including membership of an approved redress scheme. Letting agencies handling client money in England must belong to an approved client money protection scheme, and must publish the required information. Fees charged to tenants also need to comply with the rules for the nation in which the property is located.
Your process should record the renewal date, certificate location and accountable director for every business-level requirement. It should also cover client money reconciliations, approval controls for payments, segregation of duties and a documented process for reporting discrepancies. The operational value is straightforward: when evidence is stored against the task, an audit does not become a hunt through inboxes and shared drives.
Anti-money laundering obligations require particular care. If your business conducts activity that brings it within the regulations, record risk assessments, customer due diligence, beneficial ownership checks where relevant, training and reporting procedures. Do not treat a copy of an ID document as a complete AML process. The level of checking should reflect the client and transaction risk, with escalation where the facts do not stack up.
Property safety and readiness
Before marketing, agreeing a tenancy or allowing occupation, the property record should show what safety documents and works are required, their expiry dates and whether the evidence has been checked. For many residential lets in England, this will include a valid gas safety record where gas appliances are present, electrical safety documentation, smoke and carbon monoxide alarm obligations, an Energy Performance Certificate, and checks against the applicable housing standards.
The detail matters. A certificate may be present but relate to the wrong address, have expired, omit an appliance, or contain observations requiring follow-up. Make the task outcome more precise than “certificate uploaded”. Require a reviewer to confirm it is valid, complete and shared with the appropriate party.
A move-in gate can prevent avoidable failures. It should not be possible to mark a tenancy ready until required documents are present, prescribed information has been issued where applicable, and unresolved safety actions have a documented decision and escalation. There are exceptions and different rules across jurisdictions, but the process should make exceptions visible rather than accidental.
For block managers, add building-specific controls: fire-risk assessment actions, communal electrical and lift inspections, contractor competence, asbestos information where relevant, planned maintenance records and resident communications. The responsible person may differ across a building, so your system must show who owns each action rather than assuming the managing agent owns every statutory duty.
Tenancy setup and deposit protection
Tenancy compliance begins before keys change hands. Confirm the identity of landlords and tenants, authority to let, ownership details, management instructions, fee disclosures and the correct tenancy documentation. In England, Right to Rent checks may apply, but they are not a UK-wide requirement. Build the check into the workflow for applicable properties and retain a clear record of the method, date, outcome and any required follow-up.
Where a deposit is taken for an assured shorthold tenancy in England or Wales, protect it within the relevant time limit and serve the required prescribed information. Your checklist should not simply show “deposit protected”. It should capture the scheme reference, protection date, amount, tenant names, prescribed information date and proof of service.
Inventory, meter readings, key records and check-in evidence are commercially important too. They are not all statutory obligations, but they reduce disputes and help teams give landlords a defensible account of the property condition. Keep them in the same workflow so operational evidence is not split from compliance evidence.
Data protection and communication records
Property teams hold passports, bank details, maintenance reports, tenancy records and sensitive correspondence. GDPR compliance needs to work at desk level, not only in a policy folder. Limit access by role, store files in approved locations, avoid sending personal data through unsecured channels and define how long records are retained.
Your checklist should include privacy notices, lawful processing records where needed, supplier data-processing arrangements, breach reporting procedures and staff training. It should also give staff a practical route for subject access requests and data corrections. The trade-off is that tighter access can create friction for a busy team. The answer is not unrestricted shared inboxes; it is clear permissions and a shared communication hub that keeps the relevant people informed without exposing every record to everyone.
Repairs, contractors and ongoing management
Compliance does not stop once a tenancy starts. Repairs can involve safety, habitability, contractor oversight and clear communication with tenants and landlords. Log the report, triage risk, assign an owner, record access attempts, preserve contractor documents and retain the completion evidence. When a repair is delayed, the record should show why, who has been updated and when the next action is due.
Contractor controls deserve their own recurring review. Check insurance, qualifications, relevant accreditations, safeguarding procedures where your work requires them, and performance against agreed standards. The cheapest contractor is not always the lowest-cost choice if poor records or repeat visits increase risk and admin.
Turn the checklist into a live operating system
A static checklist helps a conscientious individual. Automated workflows help an agency perform consistently at scale. Set recurring reminders well before expiry, create task queues by team member and trigger escalations when a critical item is overdue. Critical tasks should not disappear beneath routine chasers.
Use status labels that make risk clear: not started, awaiting document, under review, compliant, exception approved and overdue. “Complete” is too vague when the next person needs to understand whether a document has merely arrived or has been verified.
Reporting is where directors gain leverage. A weekly view of certificates due in 30, 60 and 90 days, deposits awaiting evidence, unresolved safety actions and overdue repairs allows intervention before service suffers. A landlord-facing dashboard can also reduce inbound update requests by showing the status of actions and documents in one place.
Prop Report can support this operational layer by turning incoming calls and messages into trackable tasks, centralising communication and giving teams and landlords better visibility without replacing their core CRM or finance system. The right setup depends on your existing stack and processes, but the outcome should be the same: fewer manual chases and clearer accountability.
Give every exception a decision trail
Some issues cannot be resolved immediately. A landlord may delay works, a tenant may refuse access, or a document may be held up by a third party. Those are not reasons to let the task vanish. Record the risk, the actions taken, the decision-maker, the deadline for review and the communication sent.
This protects the agency operationally and makes patterns visible. If the same landlord repeatedly blocks safety work, or the same supplier regularly misses documents, management has the evidence to change the relationship or escalate it appropriately.
The best compliance process is quiet. It does not rely on last-minute calls, heroic admin or one person knowing where every file lives. Give every obligation a visible owner and a visible next action, and your team can spend more time managing properties well rather than proving, after the fact, that it tried to.
