Safeguarding Before and After CASS 15: What the FCA Actually Changed

Sam Kyazymov
Sam Kyazymov
Founder & CEO, ComplyOS
Aug 11, 2026GuideUnited KingdomUnited Kingdom43 views23 min read
Safeguarding Before and After CASS 15: What the FCA Actually Changed — cover image

The easy version of this story is "the FCA tightened safeguarding rules in 2026." That's true, but it skips the part that actually matters if you're trying to understand what changed and why. CASS 15 did not introduce requirements from nothing — the FCA had already been telling firms, in writing, for years, that daily reconciliations and annual safeguarding audits were expected. What changed is that those expectations moved from guidance a firm could interpret loosely to rules with defined mechanics, specific thresholds, named individual accountability, and a monthly return that makes non-compliance visible to the regulator whether or not it ever gets asked about. Understanding that distinction — guidance versus rule — is the difference between reading this as a genuinely new burden and reading it as what it actually is: the FCA writing down, precisely, what it had already been asking for.

What Safeguarding Was Actually Built On, Before CASS 15

Until 7 May 2026, the entire safeguarding obligation for a UK EMI or payment institution rested on two short provisions: Regulation 20 of the Electronic Money Regulations 2011 and Regulation 23 of the Payment Services Regulations 2017, each setting out the basic requirement to protect relevant funds and the two permitted methods — segregation, or an insurance policy or comparable guarantee. Everything beyond that bare statutory text sat in the FCA's Approach Document, in a chapter of guidance rather than a chapter of rules — non-binding in the strict legal sense, but heavily relied on in practice and, as the FCA's own account of the problem makes clear, unevenly followed.

The FCA's own diagnosis of this gap is stated plainly in the consultation paper that led to CASS 15, published September 2024: "While we have issued guidance on these provisions in our Approach Document, there remain poor practices across the industry due to poor implementation of the regulatory framework." That sentence is doing a lot of work — it isn't saying the guidance was wrong or unclear, it's saying guidance alone wasn't achieving compliance.

What the FCA Was Already Expecting, Before Any of It Was a Rule

This is the part most accounts of the CASS 15 reform skip, and it's the part that actually explains what changed. The FCA's March 2023 letter to the CEOs of every firm in its payments portfolio — a real, specific, on-the-record document, not a general warning — named three common safeguarding failings directly: firms not having documented processes for consistently identifying which funds are "relevant funds," inadequate reconciliation procedures, and a lack of due diligence and acknowledgement of segregation from the credit institutions holding safeguarding accounts. It then set out, in the same letter, exactly what it expected firms to do about each one — including reconciling "at least once a day."

That's worth sitting with: daily reconciliation was already the FCA's stated expectation in 2023, communicated in a letter with real consequences attached (an auditor's obligation to report non-compliance, a firm's obligation to notify the FCA in writing without delay). It just wasn't yet a rule with a defined mechanism — no specific definition of what a "reconciliation day" meant, no prescribed treatment for a discrepancy found the day after, no monthly return making the pattern visible across the whole sector at once. The same letter reveals the audit expectation had the same shape: in July 2020, the FCA had already issued guidance — since folded into the Approach Document — requiring firms that undertake a statutory audit to also conduct an annual audit of their safeguarding arrangements specifically. The 2023 letter's own assessment of how that went: "some firms have not yet appointed auditors and we are not being consistently informed of adverse findings or the actions being taken to address them."

So the honest version of "what changed" isn't "new expectations." It's: expectations that already existed, unevenly followed, formalised into rules with enough specificity that "unevenly followed" stops being an option.

The Evidence That Guidance Wasn't Enough

The FCA didn't move to binding rules on a hunch. The consultation paper that led to CASS 15 states, as its central justification: "For firms that became insolvent between Q1 2018 and Q2 2023, there was an average shortfall of 65% in funds owed to clients." That's not a rounding error in a handful of cases — over a five-year window, firms that failed were, on average, missing nearly two-thirds of what they owed their own customers, despite a safeguarding regime that had existed the entire time.

The same document adds a second, independent data point: in 2023 alone, the FCA opened supervisory cases relating to approximately 15% of all firms that safeguard — one in roughly every seven — specifically to address concerns about their safeguarding arrangements. That's not a tail of bad actors; at that rate, safeguarding concerns were a mainstream supervisory finding, not an edge case.

There's a third strand worth knowing, because it's a genuine legal gap rather than just a compliance one. Two Court of Appeal and High Court judgments — Ipagoo LLP [2022] EWCA Civ 302, and Allied Wallet [2022] EWHC 1877 (Ch), which extended the same finding to the PSRs — ruled that the EMRs and PSRs, as written, do not create a statutory trust over the funds a firm safeguards. In practice, that meant a customer's claim to their own safeguarded money on a firm's insolvency rested on a less certain legal footing than most people would assume "safeguarded" implies. CASS 15's proposed end-state regime (see below) exists specifically to close that gap — a rare case where you can point to two named court judgments as the direct cause of a specific regulatory reform.

What Actually Changed, Area by Area

Reconciliation

Daily reconciliation was already the FCA's stated expectation from the March 2023 letter, but it existed as guidance rather than mechanism — nothing defined what counted as a reconciliation day, or how a discrepancy spotted the following morning should be handled. CASS 15.8 closes both gaps. It builds a formal "reconciliation day" concept and requires two reconciliations on that cadence, not one: an internal reconciliation against the firm's own records, and an external reconciliation against independent evidence such as bank statements. It then adds a check that has no real precedent in the old guidance at all — a specific "D+1" position, taken the day after the last reconciliation, precisely to catch a firm whose month-end aggregate looked fine but whose day-to-day segregation was briefly under-covered in between reconciliation points. REP027 — the new monthly return discussed below — exists largely to make this cadence, and the D+1 position specifically, visible to the FCA every month rather than only when an auditor happens to look.

Reconciliation Discrepancies and Breaches

CASS 15.8 doesn't stop at requiring reconciliation — it also prescribes, in detail, what has to happen the moment the two sides don't match, and the mechanics differ depending on which kind of discrepancy it is.

An internal discrepancy — where the firm's own resource figure doesn't match what its own records say it should be holding — has a hard, same-day fix. CASS 15.8.50R requires the firm to determine the reason for the discrepancy, and then either pay any shortfall into a relevant funds bank account, or withdraw any genuine excess, by the end of the day the reconciliation was carried out. There is no grace period built into the rule: a shortfall identified today has to be closed today, not investigated first and closed once the cause is confirmed.

An external discrepancy — where the firm's own records don't match independent evidence, such as a bank statement — works differently, because the cause is less likely to be entirely within the firm's control. CASS 15.8.56R requires the firm to investigate the reason and take all reasonable steps to resolve it without undue delay, with an explicit carve-out for gaps that are genuinely explained by timing differences alone, such as a payment still in transit. Until an external discrepancy is properly resolved, CASS 15.8.57R sets a deliberately conservative default: the firm must assume, until the matter is finally settled, that whichever record shows the larger amount owed is the accurate one — meaning if its own books show less than the bank statement implies it should be holding, it has to fund the difference from its own money immediately, rather than wait for an explanation before topping up.

The "material versus non-material" distinction is worth being precise about, because the Handbook doesn't actually draw that line the way it's sometimes described. There's no fixed percentage or defined threshold in CASS 15.8 that separates a material discrepancy from a non-material one, and every discrepancy — large or small — gets the same same-day-or-without-undue-delay treatment described above. What materiality actually governs is a separate question: whether the FCA gets told. CASS 15.8.60R requires a firm to notify the FCA without delay if it materially fails to carry out a reconciliation as required, or materially fails to resolve a discrepancy it has identified. That's a notification trigger, not a two-tier remediation process — a firm doesn't get to treat a "non-material" discrepancy as optional to fix, it just doesn't automatically have to escalate a small, promptly-resolved one to the regulator.

That leaves a genuine judgement call sitting inside an otherwise mechanical regime: deciding what counts as a material failure to reconcile or resolve, for the specific purpose of triggering a CASS 15.8.60R notification. Because the Handbook doesn't define that threshold numerically, it's worth having your own documented escalation criteria — agreed with your board, tied to your CASS 15.2.4R oversight function (below), and referenced consistently — rather than making that call for the first time under pressure on the day a real discrepancy actually shows up.

Independent Audit

The audit expectation existed before CASS 15 too, but only as guidance — since July 2020, firms already subject to a statutory audit were expected, in the Approach Document, to have their safeguarding arrangements audited annually as well. What that guidance never did was set a formal bar for who was actually qualified to perform that audit, and the 2023 Dear CEO letter's own complaint — that the FCA wasn't being "consistently informed of adverse findings" — is partly a symptom of that gap: with no defined eligibility standard, the quality and rigour of "an annual safeguarding audit" could vary enormously between one reviewer and the next.

SUP 3A.3R closes that gap by making the audit a binding annual requirement, submitted to the FCA, with a carve-out for firms safeguarding under £100,000 of relevant funds across any 53-week period. Just as importantly, it sets who can actually do the work: a qualified auditor, meaning someone eligible for appointment as a statutory company auditor under Part 42 of the Companies Act 2006 — in practice, a Registered Auditor who is a member of a Recognised Supervisory Body such as ICAEW or ACCA — and independent of the firm being audited. The obligation no longer depends on whether a firm happens to already be subject to a statutory audit for other reasons, and it no longer depends on whoever the firm considers "independent enough" internally; it's a standalone requirement, met by a defined class of external professional. Submission timelines are specific too: the first audit report is due within six months of the audit period ending, and every subsequent one within four months — the first deadline was itself extended from the four months originally proposed, after the FCA acknowledged that a qualified-auditor requirement layered on a new FRC audit standard could genuinely constrain how much capacity the audit sector has to absorb the work in year one.

CASS Oversight Responsibility

CASS 15.2, the sourcebook's organisational-requirements chapter, introduces something with no real precedent in the EMRs, the PSRs, or the pre-2026 Approach Document at all: a named, accountable individual for safeguarding. CASS 15.2.4R requires a safeguarding institution to allocate to a single director or senior manager — someone of "sufficient skill and authority" — explicit responsibility for overseeing the firm's operational compliance with the relevant funds regime, and for reporting on that oversight to the firm's governing body.

In practice, most firms already had an unofficial answer to "who owns safeguarding" — usually whoever sat in operations or finance and happened to inherit it. What CASS 15.2.4R changes is that this now has to be a documented, accountable allocation with a direct reporting line to the board, not a responsibility that exists informally wherever it happened to land. The rule itself doesn't require the role to be held by a Senior Manager under the Senior Managers & Certification Regime, but for a firm that already has SMF holders, the obvious practical question is whether this specific responsibility should be written into an existing Statement of Responsibilities or documented as a standalone allocation — and leaving it undocumented anywhere formal is exactly the kind of gap that's easy to create by accident and genuinely awkward to explain to a supervisor after the fact.

Regulatory Reporting

Before CASS 15, there was nothing standing at all — the FCA's visibility into a firm's safeguarding position came from ad-hoc supervisory requests, an annual audit where one actually existed, or a firm's own notification if something had already gone wrong. The monthly REP027 return under SUP 16.14A is the first regulatory return of its kind for this sector, and it's worth being specific about what it actually asks for, because "reports on safeguarding" understates how granular it is.

Each month, a firm reports its safeguarding resource and requirement broken into components — the aggregate relevant-funds bank balance, anything segregated but not yet banked or invested, the value of any qualifying relevant assets, and anything covered by insurance or guarantee — rather than a single top-line figure, so that a mismatch can be traced to a specific cause instead of showing up as an unexplained gap. It reports that same resource-versus-requirement comparison twice over: once as at the firm's last internal reconciliation, and again specifically at the D+1 position described above, to catch a firm whose monthly aggregate looks acceptable while its day-to-day segregation was briefly under-covered. It reports, as a plain yes or no, whether internal and external reconciliations actually happened on every reconciliation day during the period — a direct test of process discipline, entirely separate from whether the resulting numbers looked fine. It reports an account-level inventory, including how many of the firm's relevant-funds accounts are covered by a current acknowledgement letter, which is consistently one of the most common gaps supervisors find. And under Section 9 of the return, it reports whether any of the specific circumstances in CASS 15.8.60R — the same notifiable-breach trigger described above — arose during the period at all.

Put together, REP027 isn't really a summary of a firm's safeguarding position. It's a monthly audit trail of the exact reconciliation and discrepancy mechanics CASS 15.8 requires, submitted whether or not anything went wrong that month. For the full field-by-field mechanics of the return itself — including the specific question IDs, the branching logic RegData applies, and what a defensible answer actually looks like — see our companion guide, How to Complete the FCA REP027 Safeguarding Return.

Acknowledgement Letters

Before CASS 15, the expectation — reflected in the 2023 letter's third named failing — was that firms should exercise due diligence and obtain acknowledgement of segregation from the institutions holding their safeguarding accounts, with no prescribed form for doing so.

CASS 15.7 turns that into a standardised, auditable document. It requires a specific template, set out in CASS 15 Annex 1, with firms prohibited from amending the letter's fixed text or changing the meaning of its variable fields, a five-year retention period after the related account closes, and a mandatory annual review of every letter on file. What was a due-diligence expectation, satisfied however a firm judged appropriate, is now a fixed document with its own binding rules about its own maintenance — and, as REP027's record-keeping section makes visible every month, a gap between a firm's account count and its acknowledgement-letter count is now something the FCA can see directly rather than only discover on audit.

Resolution Pack

Before CASS 15, there was no standing obligation to maintain one at all. Now, a safeguarding institution has to maintain a continuously updated CASS resolution pack under the related CASS 10A sourcebook — not something assembled after the fact once insolvency looks likely, but a live set of records an administrator can use from day one. CASS 10A.1.2G explains why the timelines matter as much as the content: the pack exists to enable the timely return of client funds in an insolvency, and to assist the authorities managing a resolution event, and both of those depend on the information being genuinely retrievable fast, not eventually.

The content requirement, under CASS 10A.2.1R, centres on a master document containing enough information to retrieve every other document in the pack — not necessarily every document consolidated physically in one place, but a genuine index a stranger to the firm could actually use. Around that master document, the pack has to include documentation identifying every institution holding relevant funds and every custodian of relevant assets, the executed agreements with each of them, copies of any insurance or guarantee policy in use, identification of the agents and distributors involved in handling or paying out safeguarded funds, the operational roles of any group members involved in the safeguarding arrangements, the procedures a third party would need to follow to access safeguarded funds and assets, the firm's own procedures for managing relevant funds and assets day to day, and identification of the specific people holding key safeguarding responsibilities — which, following the new CASS 15.2.4R oversight requirement above, should now name the director or senior manager holding that role specifically.

The retrieval timelines are concrete rather than aspirational. CASS 10A.1.7R requires the firm, or an administrator standing in its place, to be able to retrieve each document in the pack as soon as practicable and, in any event, within 48 hours. A narrower subset of the most operationally critical items — CASS 10A.1.9E names master identifiers, the executed third-party agreements, reconciliation records and individual staff identifications among them — has to be retrievable immediately, not within the broader 48-hour window. And the pack is not a point-in-time exercise: CASS 10A.1.11R(2) requires any material inaccuracy to be corrected within five business days of the change that caused it. In practice, that means the resolution pack has to sit inside the same operational rhythm as daily reconciliation and ongoing record-keeping — updated as things change — rather than revisited once a year alongside the audit.

Safeguarding Methods

The underlying choice hasn't changed — segregation, an insurance policy, or a comparable guarantee remain the same three options they always were. What's new is the process wrapped around the insurance/guarantee route specifically. CASS 15.5.7R now requires a firm to notify the FCA at least two months before it first relies on the insurance or guarantee method, before it changes the amount of cover provided, or before it changes insurer or guarantor. CASS 15.5.10R separately requires a firm to decide whether it intends to continue using the method, and to notify the FCA of that decision, at least three months before an existing policy or guarantee expires. Neither obligation existed in any defined form before CASS 15 — a firm could change insurer or let cover lapse and renew without a prescribed notice period to the regulator either way. The method itself is unchanged; the discipline around choosing, changing and renewing it is genuinely new.

What's Still Guidance, Not a Rule Yet

It's worth being precise about where this reform actually stops, because overstating it undersells the genuinely significant part that's still to come. Everything above is the interim regime — in force since 7 May 2026, and explicitly designed by the FCA to "supplement," not replace, the underlying EMRs and PSRs safeguarding provisions. The end-state regime — which would impose an actual statutory trust over safeguarded funds, closing the legal gap Ipagoo and Allied Wallet exposed, and would at that point genuinely replace rather than sit alongside the EMR/PSR provisions — has not been implemented. The FCA's own consultation paper says explicitly that the end-state rules depend on a further legislative step (the formal revocation of the EMRs/PSRs safeguarding provisions under the Financial Services and Markets Act 2023) that hasn't yet been commenced. Treat any claim that a statutory trust is now in place as premature — it's the proposed next stage, not the current one.

What This Means for Your Firm

If your safeguarding framework was already built around the FCA's 2020–2023 guidance — genuine daily reconciliations, a real annual safeguarding audit, actual due diligence on your safeguarding institutions — the practical change here is smaller than the headlines suggest: you're formalising and evidencing what you should already have been doing, primarily through REP027's monthly reporting cadence and a resolution pack that turns existing records into a genuinely retrievable set. If your framework was built to the letter of the bare EMRs/PSRs and treated the Approach Document's guidance as aspirational rather than operational, the gap is real on several fronts at once — a resolution pack that doesn't yet exist, a safeguarding oversight role that's never been formally allocated, an audit relationship with someone who may not meet the qualified-auditor bar — and it's now visible to the FCA every month rather than only when something goes wrong. Either way, the underlying test hasn't changed since 2023: can you show, not just say, that the right amount of customer money is protected, reconciled and recoverable, on any given day, not just when you happen to be asked.

How ComplyOS Can Help

Most of what's changed here isn't conceptually difficult — it's operational: a reconciliation process that actually runs on a defined cadence, a resolution pack that's genuinely current rather than reconstructed under pressure, a named individual who owns oversight rather than a responsibility nobody quite has, and an audit relationship with someone who meets the qualified-auditor bar SUP 3A now sets. Building or upgrading that framework from scratch, under deadline pressure, alongside everything else a growing EMI or payment institution has to manage, is exactly where firms tend to fall behind. ComplyOS's Consulting & Assurance service is built for precisely this: designing a safeguarding framework — segregation and reconciliation processes, resolution pack structure, the CASS 15.2.4R oversight allocation, REP027-ready record-keeping — that holds up under audit and under FCA scrutiny, not just on paper. If you're assessing where your current arrangements actually stand against CASS 15 rather than starting from zero, that's a conversation worth having before your first REP027 submission, not after.

Sources

  • FCA Consultation Paper CP24/20, Changes to the safeguarding regime for payments and e-money firms (September 2024), paragraphs 1.2, 1.3, 1.16, 1.17, 2.1, 2.4, 2.13–2.15 — fca.org.uk
  • FCA, "16 March 2023: FCA Priorities for Payments Firms" (Dear CEO letter, portfolio letter) — fca.org.uk
  • FCA Handbook, CASS 15 (full sourcebook structure, 15.1–15.8 and Annexes 1–2) — handbook.fca.org.uk
  • FCA Handbook, CASS 15.2 (Organisational requirements), rule 15.2.4R — handbook.fca.org.uk
  • FCA Handbook, CASS 15.5 (The insurance or guarantee method), rules 15.5.7R and 15.5.10R — handbook.fca.org.uk
  • FCA Handbook, CASS 15.7 (Acknowledgement letters) — handbook.fca.org.uk
  • FCA Handbook, CASS 15.8 (Records, accounts and reconciliations), rules including 15.8.50R, 15.8.56R, 15.8.57R and 15.8.60R — handbook.fca.org.uk
  • FCA Handbook, CASS 10A (CASS resolution pack), rules and guidance including 10A.1.2G, 10A.1.7R, 10A.1.9E, 10A.1.11R and 10A.2.1R — handbook.fca.org.uk
  • FCA Handbook, SUP 3A (Auditor's report on client assets/safeguarding), including the SUP 3A.3R qualified-auditor and annual audit requirement — handbook.fca.org.uk
  • Companies Act 2006, Part 42 (Statutory auditors) — legislation.gov.uk
  • FCA Policy Statement PS25/12, Changes to the safeguarding regime for payments and e-money firmsfca.org.uk
  • FCA, Payment Services and Electronic Money – Our Approach, version 8 (7 May 2026), Chapter 10 — fca.org.uk
  • The Electronic Money Regulations 2011, Regulation 20 — legislation.gov.uk
  • The Payment Services Regulations 2017, Regulation 23 — legislation.gov.uk
  • Ipagoo LLP (in administration), Re [2022] EWCA Civ 302 — bailii.org
  • Allied Wallet, Re [2022] EWHC 1877 (Ch) — bailii.org
  • SUP 16.14A (the REP027 return) — see our companion piece, How to Complete the FCA REP027 Safeguarding Return
SafeguardingCASS 15PS25/12ComparisonUKResolution PackAML Audit
Sam Kyazymov
Sam Kyazymov
Founder & CEO, ComplyOS

CASS 15 didn't invent new safeguarding expectations out of nothing — it took requirements the FCA had already been asking for by letter and guidance, and turned them into binding rules with defined mechanics, named accountability and hard timelines. Here's exactly what changed, clause by clause, with the evidence for why.

Need tailored guidance?

Talk to our team about what this means for your firm.