The FCA's strengthened safeguarding regime has introduced a formal independent safeguarding audit framework for relevant payment institutions and electronic money institutions.
It is commonly described as the CASS 15 annual audit because the auditor tests compliance with the safeguarding regime in which CASS 15 plays a central role.
Technically, however, the audit requirements sit in SUP 3A rather than CASS 15 itself.
That distinction matters because firms need to understand the precise scope, exemption, reporting period and submission requirements rather than relying on shorthand.
For institutions within the regime, the audit is a reasonable assurance engagement and the auditor's safeguarding report is addressed to the FCA.
Which firms require a CASS 15 safeguarding audit?
SUP 3A applies, subject to the exemption, to authorised payment institutions authorised to carry out relevant payment services and to electronic money institutions.
The FCA provides an exemption based on the value of safeguarded relevant funds.
An institution is exempt where it has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks.
The wording is important.
This is not simply a test of the firm's balance at its financial year end.
Senior management should determine on a continuing basis whether the institution remains exempt and appoint an auditor if the institution ceases to qualify.
Firms approaching the threshold should therefore monitor their safeguarding position rather than waiting for the year-end audit process.
Is the safeguarding audit annual?
The auditor's safeguarding report must cover a period ending not more than 53 weeks after the relevant starting point or the end of the previous reporting period.
In normal operation this produces an annual cycle, which is why the requirement is commonly referred to as an annual safeguarding audit.
The precise reporting period should nevertheless be agreed with the auditor and assessed against SUP 3A.
Newly in-scope institutions should establish their first reporting period and submission timetable early rather than assuming that it will automatically mirror the statutory financial-statement audit.
What does the safeguarding auditor report on?
SUP 3A requires the external auditor to prepare a safeguarding report addressed to the FCA.
The report must be prepared as a reasonable assurance engagement.
The auditor must state whether, in its opinion, the relevant institution maintained systems adequate to enable it to comply with the relevant funds regime throughout the period.
The auditor must also address whether the institution was in compliance with the relevant funds regime at the end of the period.
The first limb is particularly important.
The audit is not merely a snapshot showing that the safeguarding bank balance was correct on the final day of the year.
The auditor considers the systems operated throughout the period.
A firm that repairs weak controls immediately before year end may therefore still have significant historical issues to explain.
What is reasonable assurance?
Reasonable assurance is a high level of assurance, although it is not an absolute guarantee.
The auditor needs sufficient appropriate evidence to support the required opinion.
For a safeguarding institution, that means the quality and accessibility of operational records throughout the period become extremely important.
The firm may need to demonstrate the operation of reconciliations, treatment of discrepancies, safeguarding account arrangements, policies and procedures, governance, relevant funds calculations, third-party arrangements and other controls within the relevant funds regime.
The exact audit work will depend on the firm's circumstances and the applicable professional requirements.
The practical conclusion is simple: audit evidence should be generated while controls are operating, not reconstructed months afterwards.
When is the safeguarding audit report due?
Under SUP 3A, the auditor must deliver the safeguarding report to the FCA within four months after the end of the period covered.
Firms should therefore work backwards from the end of the reporting period.
Waiting until the period has ended before discussing scope, evidence, data access and testing with the auditor creates unnecessary execution risk.
The institution is also required to cooperate with the auditor and should provide appropriate access to accounting records, documents and other relevant information.
Does the same auditor need to perform the statutory financial audit?
Not necessarily.
SUP 3A requires the institution to appoint an external auditor meeting the relevant qualification, skill, resources and experience requirements.
The auditor appointed for safeguarding purposes does not necessarily need to be the same firm performing another statutory audit, although it may be.
The choice should be based on whether the auditor has appropriate expertise to perform the safeguarding work.
For boards, this is important.
Safeguarding is a specialised regulatory control environment. The institution should assess the proposed auditor's relevant experience rather than treating the engagement as an automatic extension of the financial-statement audit.
What evidence will firms need?
The precise evidence request will vary, but firms should expect safeguarding audit work to depend on reliable records across the full control framework.
That can include:
[safeguarding policies and procedures](/services/safeguarding) relevant funds calculations internal safeguarding reconciliation records external safeguarding reconciliation records evidence of discrepancies and how they were resolved bank and relevant third-party information acknowledgement arrangements where applicable governance and oversight records board or committee reporting safeguarding account information relevant third-party due diligence and appointments regulatory reporting records [resolution-pack information](/insights/cass-15-resolution-pack) breach and notification records * evidence explaining changes to the safeguarding methodology
The important feature is consistency.
Where several systems produce different versions of the same safeguarding position, the audit process can become substantially harder.
Why daily evidence determines annual audit readiness
CASS 15 requires firms to record information concerning each required internal and external safeguarding reconciliation.
That recurring evidence becomes highly relevant to the annual audit.
If a firm completes hundreds of reconciliation processes during an audit period but retains only the final spreadsheet output, it may struggle to demonstrate the operation of the control.
A better evidential record shows when the reconciliation took place, which information was used, what the result was, which discrepancies arose and what actions followed.
Annual audit readiness is therefore largely created by good daily operations.
How Safeheld can support CASS 15 audit readiness
Safeheld is designed to connect safeguarding reconciliation, exception management, regulatory reporting, resolution information and audit evidence.
For audit purposes, this can reduce the amount of manual evidence assembly required at the end of the period.
Reconciliation histories, supporting source information, exceptions and investigation records can be retained as part of the operating control rather than being gathered retrospectively from separate spreadsheets, emails and folders.
This does not determine the auditor's opinion.
It can, however, make the firm's control environment easier to inspect and evidence.
The strongest audit technology is therefore not software that "passes the audit". It is software that preserves reliable evidence of what the firm actually did throughout the year.
What happens when the auditor identifies breaches?
A firm should expect the audit process to identify areas requiring explanation or remediation where weaknesses exist.
SUP 3A provides for the institution to consider the draft safeguarding report and provide information explaining circumstances giving rise to identified breaches and any remedial action undertaken or planned.
The final report is also required to be reported to the institution's governing body.
The FCA expects the safeguarding report to be used as part of the firm's risk management and decision-making.
Boards should therefore avoid treating the report as an annual compliance document that is filed after approval.
An audit finding should feed directly into remediation, control design and ongoing safeguarding oversight.
Should firms conduct a pre-audit review?
For firms approaching their first safeguarding audit under the strengthened regime, a focused pre-audit review can be valuable.
The objective is not to predict or influence the independent auditor's opinion.
It is to determine whether the firm's actual safeguarding framework is complete, documented and capable of producing the evidence an auditor is likely to require.
Buckingham Capital Consulting provides specialist safeguarding and CASS 15 advisory support, including safeguarding gap analysis, reconciliation reviews, policies and procedures, audit readiness and remediation.
This can be particularly useful where the firm knows that processes remained manual during part of the period, where safeguarding arrangements changed during the year or where previous compliance concerns remain unresolved.
A practical CASS 15 audit readiness checklist
Before the audit begins, management should establish:
- whether the firm is within SUP 3A or qualifies for the exemption
- the exact safeguarding reporting period
- the four-month FCA submission deadline
- whether an appropriately qualified and experienced auditor has been appointed
- whether the auditor has sufficient system and record access
- whether reconciliation evidence exists across the complete period
- whether exceptions and breaches can be explained
- whether regulatory returns reconcile to underlying records
- whether safeguarding policies reflect actual operations
- whether the CASS resolution pack is current
- whether board and senior-management oversight is evidenced
- whether known weaknesses have documented remediation plans
A firm that can answer these questions before fieldwork begins will usually be in a much stronger position than one assembling its safeguarding history after receiving the first audit evidence request.
Frequently Asked Questions
No. SUP 3A contains an exemption where the institution has not been required to safeguard more than £100,000 of relevant funds at any time for a period of at least 53 weeks. Senior management should monitor exemption status on a continuing basis.
The safeguarding controls being audited include CASS 15 requirements, but the formal external audit regime is principally contained in SUP 3A.
The safeguarding report must be prepared as a reasonable assurance engagement.
The auditor must generally deliver the safeguarding report to the FCA within four months after the end of the period covered by the report.
Safeheld can support audit readiness by preserving reconciliation records, exceptions, investigation evidence and related safeguarding information throughout the audit period. The independent auditor remains responsible for conducting the engagement and forming its opinion.