The annual safeguarding audit under SUP 3A examines whether an in-scope payment or electronic money institution maintained adequate systems to comply with the relevant-funds regime throughout the period and complied at the reporting date.
Audit readiness cannot be produced in the weeks before the auditor arrives. The evidence is created by daily operation: source records, reconciliations, shortfall correction, approvals, notifications, reporting and change control.
## Who requires an audit?
The audit rules sit in SUP 3A of the Financial Conduct Authority Handbook. Their application depends on the type of safeguarding institution and the detailed exemption.
PS25/12 introduced a threshold intended to remove the mandatory audit burden for smaller institutions that have not been required to safeguard more than £100,000 of relevant funds at any time over the specified period of at least 53 weeks.
The firm should document its exemption assessment and preserve the balances supporting it. Falling below the threshold at the period end does not by itself establish that the condition was met throughout the relevant period.
Audit period and deadline
The reporting period must not exceed 53 weeks. The applicable delivery timetable depends on whether the report is the first report or a subsequent report and on the detailed SUP 3A provisions.
The firm should confirm its period end, appointment timetable and report deadline with the proposed auditor rather than rely on a generic calendar. A late appointment can restrict available evidence and create avoidable delay.
The auditor reports to the Financial Conduct Authority. Management should therefore treat unresolved findings as regulatory matters, not merely recommendations from a financial-statement audit.
What the auditor tests
The audit is concerned with systems and compliance across the period. Testing can cover:
- relevant-funds identification and allocation;
- the safeguarding requirement and resource methodology;
- internal and external reconciliations;
- shortfall and excess correction;
- safeguarding accounts and acknowledgement letters;
- third-party due diligence;
- records and retention;
- notifications and breaches;
- governance and senior-manager oversight;
- REP027 consistency;
- the CASS 10A resolution pack; and
- technology and access controls supporting the process.
The precise scope and sampling are matters for the auditor applying the relevant rules and professional standard.
Evidence of operation
A policy describes intended control. Audit evidence shows the control operated.
For each sampled reconciliation, the firm should be able to produce the original sources, population-completeness checks, approved methodology, calculation, exceptions, corrections, preparer and reviewer. A signed summary without those components may not demonstrate how the figure was produced.
Evidence should be contemporaneous. A control reconstructed after year end may explain what probably happened but cannot replace a record created when the control operated.
Reconciliation evidence
The auditor is likely to examine whether both internal and external reconciliations were completed at the required frequency and using reliable data.
The firm should preserve the reconciliation point, source time, rule version, safeguarding requirement, safeguarding resource, external confirmations, adjustments and outcome. Where a source was late or incomplete, the exception and escalation should be visible.
Repeated unexplained timing differences, unsigned workbooks or reconciliations reviewed long after completion can indicate that the process did not operate as designed.
Shortfalls and breaches
An identified shortfall should link to funding evidence, cause, duration, affected amount and review. The original shortfall should remain visible rather than being replaced by the corrected balance.
The firm should also preserve its assessment of whether an event was a breach and whether notification was required. The auditor may compare case records with REP027, board reporting and regulatory correspondence.
If those sources show different event populations, management should resolve the inconsistency before the audit rather than prepare separate explanations.
Technology controls
Where safeguarding evidence is generated by a system, the auditor may consider controls over that system. Relevant areas include user access, privileged administration, change approval, rule versions, backup, incident handling and the ability to reproduce historical results.
A spreadsheet is also technology. Weak access, undocumented formula changes and overwritten versions can reduce the reliability of evidence even where the closing number is correct.
The firm should maintain an inventory of systems and end-user tools supporting safeguarding and identify which controls protect their integrity.
REP027 and audit consistency
The monthly return should be derived from the same controlled safeguarding record tested by the auditor. Audit samples, filed returns and board information for the same date should therefore agree or contain an explicit reconciled explanation.
A reporting adjustment outside the safeguarding system should be visible, approved and traceable. Otherwise, the auditor may be unable to establish which record represented the firm's actual position.
Read our REP027 safeguarding return guide for the monthly process.
Resolution-pack testing
The CASS 10A resolution pack should remain current throughout the period. The auditor may examine whether the required documents existed, were updated promptly and could be retrieved within the prescribed timeframe.
Timed retrieval testing is useful evidence. The test should begin without advance preparation, record the documents produced, identify missing or stale items and track remediation.
A folder that is refreshed only for the audit is not evidence of continuous resolution readiness.
Preparing for the audit
Preparation should begin with a self-assessment rather than document collection.
- Confirm whether the institution is in scope or exempt.
- Agree the audit period and appointment timetable.
- Map each requirement to a control, owner and evidence source.
- Test a sample from across the period.
- Reconcile breach, REP027 and board populations.
- Review access and change controls over supporting systems.
- Perform a timed resolution-pack retrieval.
- Correct control weaknesses, not only missing documents.
- Provide the auditor with an indexed evidence catalogue.
- Track findings to accountable remediation.
How Safeheld supports audit evidence
Safeheld is a specialist regulatory technology platform for safeguarding reconciliation, regulatory reporting and compliance evidence. It can help firms retain source-linked runs, exceptions, approvals and reporting evidence throughout the period rather than rebuild them at audit time.
Regulatory Counsel can advise on scope, methodology and remediation. The auditor remains independent and determines the work needed for the engagement.
Speak to Regulatory Counsel
Regulatory Counsel's safeguarding practice can conduct an audit-readiness or remediation review. Safeheld can separately demonstrate the operational evidence workflow.
Frequently Asked Questions
No. Application depends on the firm's status and the detailed exemption, including the £100,000 relevant-funds condition.
The audit period must not exceed 53 weeks. Firms should confirm the applicable first and subsequent reporting deadlines under SUP 3A.
No. It is a regulatory engagement focused on safeguarding systems and compliance under the relevant-funds regime.
It may do so where systems and end-user tools produce or protect the safeguarding records on which the audit relies.
No. Safeheld supports operational evidence. The required audit must be performed by an appropriately qualified and independent auditor.
Official sources
This article provides general guidance. The requirements applicable to a firm depend on its permissions, products and arrangements.
Definitive guides on this topic
The permanent reference pages this article relates to.
Safeguarding and CASS 15
Safeguarding arrangements, reconciliations and the CASS 15 regime.
UK Electronic Money Institution licence
FCA EMI requirements, EUR 350,000 capital, safeguarding, cost and timeline.
UK Authorised Payment Institution licence
FCA API requirements, own funds methods, safeguarding, cost and timeline.