Most of what's been published on REP027 so far describes it in outline — what it is, roughly what it covers, when it's due. None of it walks through the actual questions the form asks, in the order it asks them, with the specific CASS 15 rule sitting behind each figure. That's the gap this guide fills. What follows is built directly from a completed submission, field by field, so you can see not just what each question means in principle but what a real, defensible answer to it actually looks like — with illustrative figures in place of any firm's actual safeguarded balances, since those numbers are exactly the kind of thing that shouldn't appear in a public guide, however useful the underlying structure is.
What REP027 Is, and the Rule That Actually Requires It
REP027 is the monthly safeguarding return introduced as part of the FCA's safeguarding reforms finalised in Policy Statement PS25/12 and delivered through CASS 15, the new chapter of the FCA Handbook that supplements — not replaces — the safeguarding obligations already sitting in Regulation 20 of the Electronic Money Regulations 2011 and Regulation 23 of the Payment Services Regulations 2017. The reporting obligation itself sits in SUP 16.14A: SUP 16.14A.3R sets the monthly submission requirement, SUP 16.14A.4R requires it to be made "by electronic means made available by the FCA" (in practice, through RegData), and SUP 16.14A.5R folds in the general complete-and-timely reporting standard from SUP 16.3 — meaning a late or materially incomplete REP027 is treated as its own reportable failing, entirely separate from whatever the underlying safeguarding position shows.
The form itself runs to as many as 17 sections, though most firms will only ever see nine of them. Sections 1 to 9 apply to every safeguarding institution; Sections 10 to 17 exist only for firms with "unrelated payment services" (UPS) — an EMI providing payment services unconnected to its e-money issuance, or an opted-in small institution or credit union reporting separately on that activity — and mirror the earlier structure for that separate scope. A pure EMI issuing e-money and nothing else will simply never see Sections 10 onward; RegData doesn't present them.
Who Has to File It, and the Scoping Test That Actually Matters
The category question at the start of the form (Section 1A, below) asks which of eight types of safeguarding institution you are — API, SPI opt-in, EMI, EMI+UPS, SEMI, SEMI opt-in, credit union, or credit union opt-in — but the more consequential question comes right after it. Section 1's second question asks whether your firm was "a relevant institution as specified in SUP 3A.1.1R(1)(a)" during the reporting period, with three possible answers: yes, no because you're not in scope, or no because you're exempt. This is the genuine gating question for the entire return — get the category question right but this one wrong, and every section that follows is built on the wrong foundation. It's worth resolving this against your actual permissions and activity each period, not assumed to be a fixed "yes" carried over unchanged from your authorisation date, since a firm's safeguarding profile can change as products and permissions change.
Key Terms, Defined Precisely
A handful of terms recur constantly through the return, each tied to a specific CASS 15 rule, and treating them as loosely interchangeable is the fastest way to fill in two sections inconsistently with each other.
Relevant funds are the customer money your firm is required to safeguard under Regulation 20 of the EMRs or Regulation 23 of the PSRs — money received from or for the execution of a payment transaction, or in exchange for e-money issued. The return never asks about your firm's own operating capital, only this pool.
Safeguarding resource is the actual amount protecting relevant funds at a given moment, built from up to four components the return asks you to break out separately under CASS 15.8.26R: the aggregate balance held in relevant funds bank accounts, any relevant funds segregated but not yet placed in such an account or invested in relevant assets, the aggregate value of relevant assets held, and the aggregate value of funds protected through insurance or a guarantee. Notably, the aggregate bank-account figure specifically excludes funds that sit in a Bank of England settlement account of the type described in Regulation 21(4A) of the EMRs or Regulation 23(9) of the PSRs — those accounts serve a different, narrower purpose and aren't counted in the general relevant-funds-bank-account total, which is an easy distinction to miss if you're pulling figures mechanically from a chart of accounts rather than checking what each account is actually for.
Safeguarding requirement is what you should be holding, broken out under CASS 15.8.30R into individual safeguarding balances calculated per CASS 15.8.31R (essentially, the sum of what's owed to each client, ignoring any client with a negative balance rather than netting it against the total) plus any amount received but not yet allocated to a specific client under CASS 15.2.5R. The return wants resource and requirement reported separately, by component, precisely so a mismatch can be traced to a specific cause rather than just showing up as an unexplained top-line gap.
Relevant assets, sometimes called secure liquid assets, are a narrow category of low-risk holdings — instruments falling within CASS 15.4.2G, meaning they meet one of the credit-quality categories in Article 114 of the UK Capital Requirements Regulation carrying a 0% risk weighting (broadly: exposures to the Bank of England or HM Government in sterling, to the European Central Bank, or to an ECAI-rated central government or central bank of equivalent quality), or units in a UCITS investing solely in such assets. Most EMIs holding relevant funds purely as cash in a segregated bank account will never need this section at all; it exists for firms whose safeguarding model actually includes qualifying investments.
Reconciliation day is a day on which your firm is required to reconcile requirement against resource — under CASS 15.8, at least once each reconciliation day, both internally against your own records and externally against independent evidence such as bank statements. It is not automatically defined as every single calendar day for every firm, but treating it as anything less than daily without being able to point to a specific, documented reason is a decision worth being able to defend on its own terms.
Notifiable breach, in the specific sense Section 9 of the return uses, means any of the circumstances described in CASS 15.8.60R — the rule's own notification-requirements list, not a general invitation to describe anything that felt imperfect during the month. Treat this as a defined trigger to check against, not a subjective judgement call.
The Return Is a Branching Form, Not a Static One
This matters enough to state before the section walkthrough: RegData does not present every field to every firm. Several questions are gateway questions that determine whether a whole block of detailed sub-fields appears at all. Whether you're asked to itemise every institution holding relevant funds, for instance, depends entirely on how you answer a single yes/no question first — answer "no" and the entire repeating block simply never appears, rather than appearing with an instruction to leave it blank. The same is true of the relevant-assets block, and of Sections 10 onward for firms without unrelated payment services. Don't be alarmed if your form looks structurally different from a colleague's at another firm, or from the field numbering below — a genuine gap in the sequence (this guide skips from question 2A to 4A, and from 12 to 16, for exactly this reason) usually means a conditional block, not an error in either firm's return.
Before You Open RegData
Have the following ready, ideally as a standing monthly process rather than something assembled under deadline pressure each time:
- Your highest and lowest safeguarding requirement figures for the period, and the workings behind them.
- A current, complete list of every institution, account, insurance policy or guarantee, and investment holding used for safeguarding — with balances, currencies, jurisdictions and, for time-restricted accounts, the fixed-term or notice-period detail.
- Signed, current acknowledgement letters for every relevant funds bank account, and a clear note of any account that doesn't have one yet.
- Your most recent internal and external reconciliation records, including the reconciliation day(s) and method used, and — separately — the specific figures from your very last internal reconciliation of the period, since several sections ask for that single most recent reconciliation's numbers rather than a period average.
- A log of anything meeting the CASS 15.8.60R notifiable-breach threshold, even if resolved within the month.
- Details of your most recent independent safeguarding audit, including the auditor's name and report date, if one has taken place.
Section-by-Section, Field by Field
Reporting Information
Before Section 1 begins, the return confirms your reporting period, due date, and reporting currency and currency units. Nothing to fill in here beyond confirming these are correct, but it's worth actually checking the due date shown rather than assuming — it's calculated from your specific reporting period, not a fixed calendar date each month.
Section 1 — Safeguarding Institution Information
1A. Category of safeguarding institution. Select from the eight categories described above. This single answer determines whether Sections 10 onward will ever appear for you, so get it right rather than defaulting to the category on your original permission if your activity has since expanded to include unrelated payment services.
2A. Was the safeguarding institution a relevant institution as specified in SUP 3A.1.1R(1)(a) during the reporting period? Yes, no-not-in-scope, or no-exempt. This is the gating question described above.
4A–4C. Prior auditor's safeguarding report detail. Where your firm has previously submitted a safeguarding report under SUP 3A.9, these fields ask for the date of that report and the name of the audit firm — a fixed list of the largest firms (BDO, Deloitte, EY, Grant Thornton, KPMG, Mazars, PwC) plus an "Other" option with a free-text field. If no report has yet been submitted, these can be answered "not provided" — but it's worth treating a genuinely blank answer here as a prompt to check your own audit timeline against the requirement (an initial audit within six months of the audit period end, subsequent audits within four months) rather than an item to leave blank indefinitely.
Section 2 — Safeguarding
5A. Was the safeguarding institution required to safeguard relevant funds under the EMRs or PSRs during the reporting period? Yes or no. A firm answering no here should have a clear, documented reason why — a "no" answer alongside evidence of holding customer balances is an immediate inconsistency a reviewer would flag.
6A. Which method(s) were used during the reporting period? Segregation only, insurance/guarantee only, or a combination of both at the same time — and this one allows multiple selections, since a firm can genuinely run both approaches concurrently, for instance segregating the bulk of relevant funds while covering a specific residual amount by guarantee.
6B. Which method was used at the time of the last internal safeguarding reconciliation carried out in the reporting period? Notably, this question only offers segregation-only or insurance/guarantee-only as answers — not a combination option — because it's asking about the method actually in effect at one specific reconciliation moment, not the range of methods used across the whole period. A firm that answered "combination" at 6A should still be able to identify a single dominant method for this specific snapshot.
7A. How many clients was the safeguarding institution safeguarding relevant funds for at the end of the reporting period? A single number. Worth reconciling against your actual active-client count from your CRM or ledger rather than an estimate, since this figure is one a supervisor can cross-check against other data you report elsewhere.
8A. Did the safeguarding institution use a non-standard method of internal safeguarding reconciliation during the reporting period? Yes or no. Non-standard methods require independent auditor approval under CASS 15 — answering yes here without being able to evidence that approval is a gap worth closing before submission, not after.
Section 3 — Balances
9A. Highest safeguarding requirement during the reporting period, in pounds. 10A. Lowest safeguarding requirement during the reporting period, in pounds. These require genuine continuous tracking through the month, not a single month-end calculation with a plausible high and low reconstructed afterwards — a firm that only knows its closing figure is answering a materially weaker version of the question being asked.
Section 4 — Safeguarding Relevant Funds
This section splits into two gated blocks, and the gating matters as much as the content.
11AA. Do you want to provide information about any relevant funds held in accounts under the segregation method during the reporting period? A yes/no gateway. Answering yes opens a repeating block, one instance per institution where relevant funds are held:
- 11A. The institution where relevant funds are held.
- 11B. The type of account — a relevant funds bank account, or another account type.
- 11C. The number of accounts containing relevant funds held with that institution.
- 11D. The total amount of relevant funds held with that institution at the end of the period, in pounds.
- 11E. Whether the account is fixed-term or subject to a notice period, banded into six ranges (1–30 days, 31–95 days, 96+ days, for both fixed-term and notice-period accounts) or marked not applicable for an ordinary instant-access account.
- 11F. The country of incorporation of the institution, as an ISO country code.
11G. A total across every institution entered in the block above — worth calculating independently and checking it matches the sum RegData produces, rather than trusting the running total blindly.
12AA. Do you want to provide information about any relevant assets held during the reporting period? A second gateway, this time for the narrower category of qualifying investments described above. Most cash-only safeguarding models will genuinely answer no here — and if you do, the detailed asset sub-fields (covering asset type, custodian and holding value, in addition to the credit-quality question below) simply won't appear.
12B. Where relevant assets are held, this asks which paragraph(s) of Article 114 of the UK CRR the asset's credit quality complies with — the form lists several, including paragraph 2 (an external credit assessment institution rating corresponding to a 0% risk weight), paragraph 3 (exposure to the European Central Bank), paragraph 4 (exposure to HM Government or the Bank of England in sterling), and paragraph 7 (exposure to a third-country government or central bank assigned an equivalent 0% risk weight). 12C provides an option to confirm the asset is not of a type referred to in CASS 15.4.2G at all, where relevant.
Section 5 — Safeguarding Resource and Requirement
This is the section the whole return exists to produce, and it's worth reading the definitions above again before filling it in, since every figure here is a component of resource or requirement as defined by CASS 15.8.
16A. Safeguarding resource from the last internal safeguarding reconciliation carried out in the reporting period, in pounds. The headline resource figure — not a period average, the figure from your most recent internal reconciliation specifically.
17A–17D break that headline figure into its four components under CASS 15.8.26R: the aggregate relevant-funds-bank-account balance (excluding the Bank of England settlement accounts described above), any relevant funds segregated but not yet placed in a bank account or invested, the aggregate value of relevant assets, and the aggregate value protected by insurance or guarantee. These four should sum to the figure in 16A — if they don't, that's worth resolving before submission, not something RegData will necessarily catch for you.
18A. Safeguarding requirement from the last internal safeguarding reconciliation carried out in the reporting period, in pounds.
19A–19B break that figure down under CASS 15.8.30R: individual safeguarding balances calculated per CASS 15.8.31R (ignoring negative client balances rather than netting them off), and amounts received but not yet allocated to an individual client under CASS 15.2.5R. A persistently large unallocated-receipts figure period after period is worth investigating in its own right — it usually points to a gap in your onboarding-to-allocation process, not a one-off timing issue.
20A. Excess or shortfall of safeguarding resource against requirement, identified at the end of the reporting period, in pounds. Entered as a positive figure for an excess, negative for a shortfall. 21A. Adjustments made to withdraw an excess or rectify a shortfall identified in 20A. A shortfall reported here without a corresponding, dated adjustment is a materially different signal to a supervisor than the same shortfall shown being actively corrected — treat this pairing as one answer, not two independent ones.
Section 6 — D+1 Segregation Resource and Requirement
22A–25A repeat the same resource-versus-requirement comparison as Section 5, but specifically as at the day after your last internal reconciliation ("D+1") — resource, requirement, any shortfall, and any adjustment made to rectify it. This section exists to catch a firm whose monthly aggregate position looks acceptable but whose day-to-day segregation is actually volatile or briefly under-covered between reconciliation points, which a purely period-level view could otherwise miss entirely.
Section 7 — Safeguarding Reconciliations
26A. Did the safeguarding institution carry out internal safeguarding reconciliation(s) every reconciliation day during the reporting period? 27A. The same question for external reconciliations. Both are yes/no, and both are a direct test of process discipline rather than outcome — a firm can have a clean Section 5 position and still answer no here if it can't evidence the reconciliation cadence that position depends on, which is precisely the gap a supervisor reading these two answers alongside Section 5 is checking for.
Section 8 — Record Keeping
28AB–28AF ask for an account-level inventory across the period: the number of relevant funds bank accounts (excluding Bank of England settlement accounts) held at the start of the period, the number opened, the number closed, the total held at the end of the period, and — critically — how many of those end-of-period accounts are covered by a current acknowledgement letter. A gap between the total account count and the acknowledgement-letter count is one of the most common and most avoidable findings in this return, and it's worth chasing outstanding letters as a standing monthly task rather than discovering the gap only when this section forces the comparison.
Section 9 — Notifiable CASS Breaches
29A. Did any of the circumstances referred to in CASS 15.8.60R arise during the reporting period? Yes or no. Answer against the rule's actual defined triggers, not a general sense of whether the month felt smooth — and resist the instinct to answer no on the basis that an issue was resolved before month-end. The question asks what happened during the period, not what remains open at the point of submission.
Sections 10–17 — Unrelated Payment Services
For an EMI+UPS, an opted-in SEMI, or an opted-in credit union reporting on payment services unconnected to e-money issuance, Sections 10 onward mirror the structure above — institution details, balances, resource and requirement, reconciliations, record-keeping and breaches — applied to that separate scope. Treat it as a genuinely independent exercise: the requirement and resource calculations, the accounts involved, and the reconciliation evidence for unrelated payment services are specific to that activity, not a restatement of Sections 1–9 under new headings.
What We See Firms Get Wrong
The pattern that matters most isn't any single field — it's ownership fragmentation. The data this return asks for genuinely sits across finance (the actual account and balance records), operations (whether reconciliations actually happened on schedule), and compliance (the regulatory interpretation of what counts as a relevant fund, a relevant asset, or a notifiable breach), and firms that haven't assigned one person to pull those three views together every month, on a fixed schedule, are the ones who find each submission harder rather than easier as the months go on. The firms who find this straightforward have simply made "resource versus requirement, reconciled and evidenced" part of how they already run safeguarding day to day — which is exactly the operational discipline this return is designed to surface, one way or the other.
Where This Sits in Your Wider Safeguarding Framework
REP027 is a reporting obligation, not a substitute for the underlying controls it reports on. See The UK EMI Regulatory Map for how Regulations 20 to 22 of the EMRs and the CASS 15 rules that now supplement them fit into your broader compliance stack, and The FCA's New Safeguarding Regime for the wider set of changes that came into force on 7 May 2026. If your firm is still building the reconciliation and record-keeping process this return depends on, rather than just the return itself, that's exactly the gap Consulting & Assurance is built to close.
Sources
- FCA Handbook, SUP 16.14A (Safeguarding return: safeguarding institutions) — handbook.fca.org.uk
- FCA Handbook, CASS 15.1 (Purpose and application) — handbook.fca.org.uk
- FCA Handbook, CASS 15.4 (Segregation: secure, liquid assets) — handbook.fca.org.uk
- FCA Handbook, CASS 15.8 (Records, accounts and reconciliations) — handbook.fca.org.uk
- FCA Handbook, SUP 3A (auditor's safeguarding report) — handbook.fca.org.uk
- The Electronic Money Regulations 2011, Regulations 20–22 and 21(4A) — legislation.gov.uk
- The Payment Services Regulations 2017, Regulation 23 and 23(9) — legislation.gov.uk
- Article 114, UK Capital Requirements Regulation (Regulation 575/2013 as onshored) — legislation.gov.uk / PRA Rulebook
- FCA, RegData — fca.org.uk/firms/regdata


