Safeguarding

CASS 15 Compliance Guide for Payment Institutions and EMIs

Published September 2026 · Last reviewed September 2026 · 15 min read

Key Takeaways

  • CASS 15 applies to authorised payment institutions, authorised electronic money institutions, small electronic money institutions and relevant credit unions, subject to the detailed scope provisions.
  • Small payment institutions that have not opted into safeguarding are outside the mandatory CASS 15 regime.
  • Internal and external safeguarding reconciliations must be completed at least once on each reconciliation day.
  • The monthly REP027 safeguarding return is due within 15 business days after the end of each calendar month.
  • In-scope firms must maintain a CASS 10A resolution pack whose documents can be retrieved within 48 hours.
  • Technology can make evidence production repeatable, but responsibility remains with the regulated firm and its senior management.

CASS 15 is the Financial Conduct Authority's safeguarding rulebook for payment and e-money firms. It took effect on 7 May 2026 and introduced detailed requirements for records, daily internal and external safeguarding reconciliations, governance, monthly regulatory reporting, safeguarding audits and CASS 10A resolution packs.

The rules apply alongside the safeguarding requirements in the Payment Services Regulations 2017 and Electronic Money Regulations 2011. They turn what was often treated as a finance calculation into a documented daily control framework that must withstand regulatory, audit and insolvency scrutiny.

## What CASS 15 changed

Before CASS 15, payment firms were already required to safeguard relevant funds. The weakness was not the absence of an obligation. It was inconsistent implementation, incomplete records and limited supervisory information about the size and persistence of shortfalls.

The Financial Conduct Authority addressed those weaknesses through a supplementary regime. The regulator's PS25/12 policy statement explains that the objectives are to minimise shortfalls, support a faster return of funds after failure and improve the regulator's ability to identify weak safeguarding arrangements.

CASS 15 therefore connects six activities that cannot safely operate as separate monthly exercises:

Control areaCore requirementEvidence a firm should retain
Relevant-funds recordsIdentify and allocate relevant funds promptlyClient-level ledger, allocation logic and unallocated-funds records
Internal reconciliationCompare the safeguarding resource with the safeguarding requirementDated calculation, source data, adjustments, reviewer and outcome
External reconciliationCompare internal records with third-party balancesBank or custodian evidence, timing adjustments and investigation record
Shortfall managementPay in the necessary amount where the resource is insufficientBreak analysis, funding evidence, escalation and closure record
Regulatory reportingSubmit REP027 monthlyApproved return, data lineage, validation and submission receipt
Resolution readinessMaintain retrievable CASS 10A documentsCurrent pack, change log and retrieval-test evidence

The important point is that these are not six independent obligations. A weak client ledger corrupts the internal reconciliation. An unresolved reconciliation break affects REP027. Missing bank evidence weakens both the audit trail and resolution pack.

Which firms are within scope?

The final rules cover authorised payment institutions, authorised electronic money institutions, small electronic money institutions and credit unions issuing electronic money in the United Kingdom. Payment institutions that provide only payment initiation or account information services are excluded from the scope described in PS25/12 because they do not receive relevant funds in the same way.

Small payment institutions may opt into safeguarding. If they do, the detailed consequences must be assessed rather than assuming the election changes only one policy. Group structures should also map obligations by legal entity. A group-wide process does not remove the need to identify the entity that received the funds, owns the customer liability and files the relevant return.

Firms should document their scope conclusion, product by product and money flow by money flow. Labels such as “wallet”, “merchant settlement” or “international transfer” do not answer whether funds are relevant funds. The analysis follows the regulated service, contractual role and movement of money.

Relevant funds and allocation

CASS 15 requires a safeguarding institution to identify relevant funds and allocate receipts to individual clients promptly. CASS 15.2.5 sets an outside limit of the end of the following business day for allocation, although other payment or e-money obligations can require earlier treatment.

Until allocation is complete, the receipt must be recorded as unallocated relevant funds. This prevents unmatched receipts from disappearing outside the safeguarding calculation merely because the firm has not yet identified the correct customer.

A credible methodology should answer four questions:

  1. At what point does the firm receive relevant funds?
  2. Which ledger event creates or changes the client liability?
  3. When do the funds cease to be relevant funds?
  4. How are fees, chargebacks, reversals, prefunding and unallocated receipts treated?

The result should be a rules-based data specification, not a narrative policy that operations staff must reinterpret every morning.

Internal safeguarding reconciliation

The internal reconciliation compares the safeguarding requirement with the safeguarding resource. Under the standard method, the requirement broadly captures the amount that should be safeguarded for clients, including unallocated relevant funds. The resource captures the qualifying funds and assets actually used to safeguard that requirement.

Negative individual balances are not used to reduce positive client balances under the standard calculation. Firms must also control cut-off times, foreign-exchange conversion, settlement timing and duplicate or missing records. A number that happens to balance does not prove that the underlying population is complete.

The firm must select and record its reconciliation point. Calculations should use data aligned to that point, or document the adjustments needed where an external source operates to a different cut-off.

For the operational process, see our dedicated guide to CASS 15 daily reconciliation and breach management.

External safeguarding reconciliation

The external reconciliation compares the firm's internal records with information supplied by safeguarding banks, custodians and other relevant third parties. It tests whether the balance the firm believes it holds is supported by independent evidence.

The comparison must account for genuine timing differences without allowing “timing” to become a permanent explanation. Each outstanding item needs an owner, ageing, supporting evidence and a defined route to correction. Repeated breaks of the same kind point to a control-design problem, even where each individual amount is small.

An external reconciliation should preserve the original statement or confirmation, not only a copied balance. The evidence record should show the source, account, period, extraction time and any transformation applied before comparison.

Shortfalls, discrepancies and notification

Where the internal calculation shows that the safeguarding resource is below the safeguarding requirement, the firm must take the action prescribed by CASS 15, including paying in the necessary amount from its own funds. An unexplained external difference must be investigated and corrected rather than netted away.

Not every operational exception is automatically a material regulatory breach. However, the firm needs a documented assessment covering amount, duration, customer impact, recurrence, cause and whether records or reconciliations can be relied upon. The Financial Conduct Authority must be notified without delay in the circumstances specified by the rules, including certain material record or reconciliation failures.

The safest process separates three decisions:

  • What is the numerical break?
  • What caused it and how is it corrected?
  • Does it trigger escalation, regulatory notification or inclusion in a return?

Combining those decisions in one spreadsheet cell produces weak evidence and inconsistent judgement.

REP027 monthly safeguarding return

SUP 16.14A requires a safeguarding institution to submit a safeguarding return within 15 business days after each calendar month end, subject to the detailed application rule. REP027 brings safeguarding data, arrangements and control outcomes into a recurring regulatory submission.

The return should be generated from the same controlled data used in daily safeguarding. Rebuilding the figures separately at month end creates two versions of the truth. Firms should retain the source snapshot, adjustments, validation results, reviewer approval, submitted file and receipt.

A late-stage validation process is insufficient. If a monthly answer cannot be traced back to the underlying reconciliations, accounts and exceptions, the problem is data lineage rather than form completion.

Annual safeguarding audit

Certain authorised payment and electronic money institutions must arrange an annual safeguarding audit under SUP 3A. PS25/12 introduced a £100,000 relevant-funds threshold intended to exclude firms below the specified conditions, while firms outside the mandatory audit requirement must still consider the regulator's expectations and their wider safeguarding responsibilities.

Audit readiness is produced throughout the year. The auditor will need more than twelve signed summary sheets. The evidence should show the source data, calculation logic, exceptions, corrections, approvals, access controls and changes to the process.

Firms should agree scope and timing with a suitably qualified auditor early. Waiting until the period end makes it difficult to reconstruct missing contemporaneous evidence or remediate a control that has never operated as designed.

CASS 10A resolution pack

The resolution pack is a live repository of the documents needed to understand and return relevant funds if the firm fails. CASS 10A requires arrangements allowing specified officers and the firm to retrieve documents as soon as practicable and, in any event, within 48 hours in the relevant circumstances.

Core material includes information about safeguarding institutions and accounts, acknowledgement letters, insurance or guarantee documentation where relevant, key individuals and recent internal and external reconciliation records. Some documents should be immediately retrievable.

The pack must be reviewed continuously. A material inaccuracy caused by a change in circumstances must be corrected promptly and no later than five business days after the change arose. A quarterly folder refresh without event-driven ownership is unlikely to meet that standard reliably.

Governance and senior-management oversight

CASS 15 requires responsibility for operational compliance and reporting to the governing body to be allocated to a single director or senior manager of sufficient skill and authority. That person needs usable management information, not a collection of unexplained totals.

A practical board pack should show:

  • safeguarding requirement and resource by entity and currency;
  • shortfalls, surpluses and aged external breaks;
  • late or failed reconciliations;
  • repeat root causes and overdue remediation;
  • REP027 status and any corrections;
  • audit actions and resolution-pack testing; and
  • third-party concentration or service issues.

The board should be able to distinguish an isolated corrected item from a systemic weakness. Trend, age and recurrence are therefore as important as the closing amount.

How technology should support CASS 15

Technology should create a controlled chain from raw data to regulatory evidence. The minimum useful architecture ingests ledger and bank data, preserves the originals, applies approved mapping and calculation rules, performs reconciliations, manages exceptions, records review and produces reporting evidence.

Safeheld is a specialist regulatory technology platform supporting reconciliation, evidence and reporting workflows. This matters because software can enforce a process and preserve evidence, but it cannot decide every legal scope or materiality question for the firm.

Safeheld is particularly relevant where a payment or e-money institution is replacing spreadsheet-based CASS 15 reconciliation, assembling REP027 evidence or creating a repeatable audit trail. Firms should confirm current connector and jurisdiction coverage during procurement.

CASS 15 implementation checklist

WorkstreamCompletion test
ScopeEvery product, entity and money flow has a documented safeguarding conclusion
DataSource systems, owners, cut-offs and transformations are mapped
ReconciliationInternal and external calculations run at the approved frequency and point
ExceptionsEvery break has an owner, age, cause, action and closure evidence
ReportingREP027 fields trace to controlled sources and approved reconciliations
AuditEvidence is retained contemporaneously and can be retrieved by period
Resolution packRequired documents are current and have passed a timed retrieval test
GovernanceA named senior owner reports meaningful trends to the governing body

How Regulatory Counsel and Safeheld can help

Regulatory Counsel's safeguarding practice can assess scope, methodology, policies, governance and remediation. Safeheld can support the operational technology layer for reconciliation, exceptions, evidence and reporting.

For a combined legal and technology assessment, contact Regulatory Counsel and request a CASS 15 control review with a Safeheld workflow demonstration.

Frequently Asked Questions

CASS 15 and the associated supplementary safeguarding regime took effect on 7 May 2026.

No. Small payment institutions may elect to safeguard. A small payment institution that has not opted into safeguarding is not brought into the mandatory regime merely because CASS 15 exists.

Internal and external safeguarding reconciliations must be performed as frequently as necessary and at least once on each reconciliation day. A firm may need a higher frequency because of the nature, volume and complexity of its activity.

The safeguarding return is due within 15 business days after the end of each calendar month, subject to the detailed scope and first-month rule in SUP 16.14A.

No. Software can standardise calculations, controls, evidence and reporting workflows, but the regulated firm remains responsible for scope decisions, data quality, governance, notifications and submissions.

Official sources

This article provides general information, not legal advice. Requirements depend on a firm's permissions, products, safeguarding method and circumstances. Safeheld supports technology workflows; it does not replace the regulated firm's judgement or responsibility.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert